Techstrong TV July 29, 2025
Watch our live stream Monday through Friday, featuring exclusive news, announcements and conversations with IT leaders and experts on topics ranging from digital transformation to #DevOps, #Cybersecurity, #CloudNative, #Containers and deep-dives into specific technologies and best practices
Transcript
You have to be a fan boy to run the new OS 26. Maybe you're watching Textron Gang. Hey everyone, happy Tuesday.
It's Alan Shimel for Textron Gang. Welcome to our Tuesday show. Uh, you know, Mike Ard, we gave him the week off, so he was, he won't be here the rest of this week, but we've got some great people to fill in for, for him of John Schwartz, primarily one of our editors here at techron.
So we're looking forward to a great week of, of Techron Gang. Uh, we've got some great stories to kick off your Tuesday for you as well as some great people to talk about it with. Let me introduce you to our gang members in attendance for today.
We have Stephen Foskett, JP Morgan, Phil John Schwartz, and Mitchell Ashley with a feline companion. Hey, Mitch, how are you, man? Good, good.
I'm, it was just vibe coding. Sorry, I'm got here. Just I got you.
She was vibe coating or you were? That's my, that's my companion Nate, my vibe coating companion. Okay.
Very cool mascot. All right. Um, so guys, let's jump right into it.
You know, John, I, I, I put up an article, uh, last week, um, Mac, well, not Mac, excuse me, apple put up, uh, public betas, developer betas, I think is the official term for the entire portfolio for the, from watch to O to Mac, to iMac, to MacBook to iPad and iPhone, all the same. It's, they're all Mac OS 26. What do you think?
So it was interesting, I read your article, it was really, really interesting and, and in a sense, the iOS 26 be public beta was released, as you said last week, and, um, you know, things could change in the final release in the fall. We're assuming we're gonna have the new iPhones probably announced in early September. And from the impression that I got from your article is that you were pleasantly surprised as our resident Apple fanboy.
And what I want to ask you about, kick it, kick off the conversation is what feature stood out to you? I know we've heard about the liquid glass interface. There was always the murmurs about Apple Intelligence and to what extent it will be in the system.
I'm wondering about those two things, but I'm also wondering if there's one platform in this release cycle that stands out the most among all of them. Sure. Good, good stuff, John.
Well, I, I will tell you the liquid, you know, beauty is in the eye of the beholder, but in this be's eye, liquid glass is very pretty. It, it maybe takes a little getting used to. It didn't take me very long, and it is very pretty, but it's eye candy, right?
I don't know if it actually enhances the user experience or, you know, more functionality. Um, what's interesting is there's a goodie in OS 26 for every single platform, but they're not all the same goodies. So each platform has its own sort of unique goodies that are in there.
Uh, for me, the biggest, you know, the biggest lift was for iPad. It really has made your iPad into a, into a, uh, a laptop replacement. Right now, I, I have two iPads.
I, I have the iPad, air, air, and I have the other Bo Bo both the 10, 11 inch one, not the massive one, but, you know, latest processors. And I use a magic keyboard on both of them. I have magic keyboards, so it was already sort of laptop ish, but now with the ability to resize my windows, multitask, have two windows open on the screen at the same time, dynamically resizing them.
And, you know, the, the, the Mac like ribbon where I can switch around, pops up, like, you know, hidden magic. Um, it really does feel like I'm working on my laptop. It, it's, you know, and it's, and it's that 11 inch factor.
It's light, it's snappy. It's still an iPad when I want it to be, you know, a tablet, you know, a big phone, whatever you want to call it. But it really, there's nothing, there's almost nothing I can't do on my MacBooks or my iMac that I can't do on my iPad now.
And I think this is gonna set it free. You're laughing, Steven. Yeah.
Can I ask just one brief follow up and I'll leave, I'll, I'll get, I'll get outta the way, but it, it compared to the last couple of years where we had a lot of incremental announcements, would you say that based on what you saw, you're more excited about what will come with an iPhone rather than say the last couple of years where it seemed to, to kind, we kind of got into this rut with Apple? Yeah, so I will tell you the big, the big changes in the iPhone, and, and keep in mind, I'm only using this over the weekend so far, right? The big changes I've seen with the iPhone, so big change for me call me shallow how, but, uh, when you're playing music, like I'm playing a playlist or a station or what have you, it actually, it doesn't like stop, you know, a song doesn't stop and then the next song starts in a second or two.
It has sort of a, like a DJ mix in, right? I was playing the, uh, the new Billy Joel, like seven hours that he released with his, uh, uh, the, the special on, on Netflix or wherever it was, or HBO Max, excuse me. And so he released this whole music, you know, con contemplation and it mixes it when I was on my boat Saturday playing, um, apple Music playlist, and it was mixing in, you know, from one song transitioning one song to the next.
That was pretty cool. Apple never did that before. But overall, I would say the biggest thing I've seen on the iPhone is despite what we heard, that there was nothing new in Apple Intelligence, there isn't anything big and flashy.
There's not, I I haven't played with Siri. I'm not a Siri person, to tell you the truth. Um, I haven't played with Siri to tell you how, if that's a big improvement.
But you could see subtle Apple intelligence, subtle ai, subtle, more intuitive, and grabbing stuff and making it more available to you easily in the, in the iOS. I, I would say that's the biggest change to the iOS, not the iPad, uh, os is, is subtle intelligence built in there. Steven, you, you were laughing.
You had something to say. Well, I, I, I am also a fan of Apple hardware and software, and I use my phone, my iPad, my Mac all the time every day. And I absolutely hate iOS 26 and Mac OS 26.
It's, it's, it's ugly. Um, it's incredibly inefficient in terms of space. Uh, the user interface metaphor makes no sense whatsoever.
It, you know, it's, it's unreadable. The things that I like about Mac O or about iOS, uh, and iPad os are actually some of the things you mentioned, like the windowing finally makes some sense. Um, but the, I I just can't get past the liquid glass.
The, the, all the UI elements are huge and waste space on the 11 inch screen. Um, even on a 14 inch MacBook Pro, the new beta of Tahoe, all of the radiuses and chamfers and popups and everything, they're so huge that they give you a lot less space to actually do anything with. And they're incredibly ugly and hard to read because, you know, the background is kind of bleeding through this alleged glass looking thing, but, um, it bleeds through too much.
So you can't actually freaking read the text anymore. I mean, I don't wanna sound like some old man here, but just give me a black flat background with white text or the opposite of that so that I can actually read it. You weren't Chasing any kids away from in front of your house this weekend.
Were you? Get off My on Don't play without your own house. It reminds me of the Aqua UI from the original Mac Os way back when, which frankly is cartoonish and awful.
And, and on the, on every platform I've tried to use this new liquid glass. I just keep saying, what were they thinking? The the dynamic island on the iPhone in the last release of iOS was so nice.
It was this cool little blobby black thing, and it like expanded and contracted and had these nice little, but it was high contrast. It was readable, it was usable. This is like that, except if it was completely illegible.
Yeah. Coming from a software development, engineering background, I can't imagine. That's what I thought about when I read your article, Alan.
I, I can't imagine how difficult it must be to be in the operating system product group these days. I mean, we are how many years into operating system advancement? And it's like, well, we can't go and say we're not changing anything.
It just, you know, would send the wrong message. But the truth of the matter is, uh, you know, where where do you expect this, you know, the upward momentum of change to occur in, in metaphors. Now, what, what would've been interesting to me with this release, given all that we've had, you know, the growth in ge uh, generative AI over the, uh, past five years, what would've been interesting would be to have seen an operating system that actually more embraced dynamic behavior based on generative ai.
Like learning about, you know, who you are and generating your UI on the flaw, right? Steven, you're like, oh, Steven doesn't like this. Let me, how would you like this, Steven?
Right? I mean, to me, that's the next level of change that has to come and the little tweaks and changes and, you know, things that occur within the product group are just wasteful a waste of time at this point. You're just, you know, spinning wheels to make an announcement.
Well, I think a, I think AC actually, apple Health has been leaking information to the OS group. 'cause every time I need to get my glasses upgraded to continue seeing the smaller and smaller user interface of the current products, uh oh, they're like, oh, we need to make 'em bigger so that the, I don't know which, which generation, but, you know, the greatest generation or our generation or the coming one, uh, can, can use these products now. I, I think, I mean, it, it is said that this is done as a overhaul and just a major design change, design improvement.
I think what's understated is they're trying to unify the UI across their devices to the degree they can. And you can argue whether that's a good thing or bad thing, or it's the lowest common denominator. So they all kind of suffer a bit to be able to support an iPhone and a Mac that has enough of the same similar properties.
It does remind me of when Microsoft moved to the ribbon menu, and I hated it. I hated the ribbon menu, and I, you know, I lambasted Microsoft on, uh, network world and Computer World and everything I wrote for saying, this is the stupidest us stupidest idea. We have to relearn how to use all your products.
Well, now nobody thinks twice about it, and people come along with it. So we'll probably end up there someday. Stephen May still hate it, but he'll, he'll get along with it.
Okay. I think, Yeah, so Apple's uh, apple's kind of in this, this Apple's kind of in this conundrum though, where they keep getting dinged. Every year they do a major announcement, not just to ww DC, but the app, the iPhone events.
So in a sense, they're, they're dinged for being too kind of conservative and not doing, doing enough. And then if they try to do something radical, they're gonna get pushback. It's something like Facebook never hesitated to make a major change.
And whether the users liked it or not, that they would've eventually adopt it. I kind of wonder if Apple finds itself kind of in the same tension. Yeah, well, I, I do think that they felt the need to do something different.
And, and I'll, I'll say the smaller the screen, the better liquid glass looks. So on the watch, I haven't used it myself, but I've seen a lot of screenshots. And by the way, six Colors has incredible reviews of these, of all of these betas.
If you really want to hear a, uh, an unvarnished and in-depth review, um, it, the Apple Watch looks, looks really sweet. And I, and in my experience, I put the beta on my phone and I actually kind of like it on the phone, but then I move to the iPad and I'm ki and I kind of don't like it. And on the Mac, I really, seriously don't like it.
So I think that it kind of gets to what JP was saying and, and what Mitch was saying, that they're trying to make a unified user interface across all of these. But, but these devices are so different that maybe we don't need a unified user interface or a look and feel. Maybe we, you know, maybe we ought to have liquid glass on the phone, but maybe not on the iPad so much.
You know, I think that that would probably solve some of these things. And JP, if, if, if I had an AI built user interface, um, it would probably be black background with green text, like a VT two 20 and, uh, no decorations at all. So, um, have added AI 2270, we need, we need those back.
Yeah, good. And like I said before, go play in front of your own house, but I, I, I did put it on my watch. I've been running it on my watch.
Other than the numbers when you first, or letters, whatever, you know, when you go to log into your watch, like put in your passcode or whatever, after that, I, I'm not seeing a huge difference in the applications what I did, you know, from a, from a, uh, a liquid glass point of view, from a functionality point of view, I kind of liked the, uh, the workout buddy. It was a little clippy kind of thingy, but, you know, it's, it's different, you know, way to go, Alan, way to go. Um, you know it, but so I, I thought that the least, I thought the watch had the least kind of change to the interface from a glass point of view, though.
There were, I, I've, you know, I'm, and I don't know this for a fact, but I heard the next generation watch is gonna be able to do a glucose monitoring, blood pressure and, and other things like this perhaps. And, and that'll remains to be seen. But, you know, I, I also have it on my big iMac screen and my iMac screen.
I run a two monitors set up with a 5K monitor next to it. And, and it does, it does not look comical on, on a real high res like that. Um, but, but you know, as I said in the beginning, beauty's in the eye of the beholder and, and it does take some getting used to, but let me mention one other thing to us and we can, we'll take comments and, and call it a day on this topic.
I'm looking forward to the new web browsers from AI and, um, oh shoot, perplexity, because Open ai. Yeah. From open AI and perplexity, excuse me.
'cause I am, I'm thinking we need a whole new paradigm. Are we done with windows and mice or is there a better way to Steven's point of communicating and your computer or device? 'cause we don't call 'em all computers anymore.
Uh, are we are coming to a better way of your interaction with your device than clicking on a window or resizing a window or clicking a button, right? Have, are we moving beyond Xerox Park after 50 years? Well, that's what I thought.
Maybe liquid glass would be a transitionary interface to NLP. And it's not, I mean, maybe, maybe Siri will be better integrated into the experience. We'll have to see.
I'm as, I'm also not a huge Siri user myself, but, and, but there's been no claims laid that this is, this is their progress towards getting there. We'll see, but, you know, we'll see what the browsers look like, like you're talking about from perplexity and open ai. Yeah, I, I would call out too, to Alan's point in the article, um, I do think that they've been making continual improvements to Siri, um, and a lot of the other AI features that have made them somewhat, slightly better, well, maybe not Siri, but many of the other ai.
And another thing I'll, I'll point out, I am a big power user. I'm a Mac Power user. Absolutely.
Um, they've done so much more in Spotlight search, it's gotten way better after being way worse in the last version of Mac Os. I mean, like, sometimes it wouldn't even find things that it should have found that are like obvious, but, um, it appears to have gotten a lot better in the beta. So I do think there's a a Lot of under the hood stuff.
Yep. There's more. Beauty is not just skin deep.
Alright, let, let's take a break on that. We're gonna come back and kind of switch gears up a little bit. Talk about, uh, AI and Sparks.
You're watching Textron Gang, Discover Textron Group, the epicenter of tech innovation. We are your go-to for reaching IT leaders and practitioners worldwide. Our secret impactful content that sparks awareness, engagement, and top quality leads with us.
You'll access editorial websites, streaming videos, virtual events, custom content analyst research, and more. Join our satisfied clients. Let's revolutionize your tech journey.
Contact us today and tell your story to the world in the most powerful way. With Textron Group, We are back with the gang. And, uh, for decades, the software development landscape has been largely defined by a fundamental tension, even a conundrum that this gap between having a brilliant idea then making it a reality.
So developers have typically navigated complex set of processes, configuration, headaches, deployment pipelines that took weeks just to establish a, to establish before writing a single line of meaningful code that might end or might be changed significantly with GitHub's latest innovation called Spark, which col, which is designed to collapse this timeline from weeks to minutes. I want to start it off with, uh, jp I'm wondering if, if you think GitHub Spark, which I believe is available now in public preview for a copilot pro plus subscribers, represents a meaningful shift in how we approach application development. Uh, this is not new.
There are a number of startups out there that are offering this capability right now. There are a number of VS code plugins that have, uh, provided this capability, uh, for developers at, at, you know, at the moment, the Claude Code, uh, is one of the more popular, uh, tools right now that is in use that will allow you to basically submit a product requirements document and develop the entire application for you from the, or at least a, you know, a rough initial, uh, you know, version of your application based on that. Some of them that are out there actually will take handwritten drawings of what the screen should look like and convert them into react JS applications.
So I don't see this as, as new, uh, or, or innovative in any way above and beyond what's out there today. Uh, I, I think it's interesting that it's kind of being what, if anything that's interesting here in this story is that GitHub, which has kind of started, if you remember from, you know, the replacement for CVS, the code repository is now becoming this hub, real hub for all aspects of development, right? And that is, you know, all those other things I mentioned, they kinda leave you stranded in the process, right?
You know, um, you're still responsible for building your DevOps pipeline around it. You're still gotta figure out how to, uh, address, you know, the changes that you wanna make, the maintenance of the application, how to deploy that. Uh, and the thing that I think Spark will add or offer the users is the ability to, to kind of get all that running, right?
I, I'm, you know, alright, spark, add me a workflow so that when I check in, it automatically deploys a, you know, spark, do this, you know, so it's, yeah, I got my app, but I also have the ability from within that environment to create the way to test and operate that new application. And, and I, and that would add to the services that are offered by some of these other startups that I mentioned. You know, jp, as I think about it, uh, the way I see the market development, we are in a transition period, to your point about software engineering, there's kind of two main paths that are, that we're going down.
One is the IDE based or the hybrid IDE where it's an IDE plus a, a chat session, an interactive session with whatever model that you're using. It can be through a web browser, it can be a plugin into your IDE, but we're still looking at code, we're still seeing it, watching it. Maybe we're analyzing it, maybe we're not, but it's contended for a more technical audience.
Uh, then there's the no code audience, which is just gimme an interface. Here's my document, here's my requirement, help me build something. That's the, the, uh, the, the Firebase Google Firebase studio kind of products.
And, and some of them have that also within the IDE, but it's still an IDE. I think this is a very conscious effort, and both of those are evolving at the same, their own paths because the IDE path is also dipping down into the CLI. Here's now you have, uh, yeah, at the C-I-C-L-I level as well as your IDE, there's a mouthful.
Um, but, but going the no code route, I think this is very intentional by GitHub to attract or expand open the kimono to a larger group of users because GitHub does not attract non-technical users. You land on GitHub and most people would say, I don't know what all those files are. It looks like a file system.
What is this thing for? But if you go into Spark, it looks like building, it looks like it's chat interface and for building an app. Now they talk about micro apps, meaning they're not trying to get too fancy or sophisticated.
So I think, I think that's part of the attention here. You could also see it as, as kind of an experiment, can they attract more users beyond the traditional developers? And I, I do see this as a fundamentally different kind of product in that it is specifically designed as you, as you pointed out, not just to write the code, but to build everything else as well.
So essentially you can say, um, I wish there was an app that would let me, I don't know, count my dog's steps while we go on a walk. And, and, and not just like, oh, well here's some code that could be useful in making that happen, but it'll literally like create the whole thing and deploy it for you in the cloud. And then baa bing bot a boom.
You're watching your dog steps the next day. The problem is, in my mind that by making it so easy, and again, I don't wanna sound okay, I'm gonna sound like the old man yelling at people. Okay, come on.
Bring it, bring it. I can take it. That's Today's, that's today's statement.
That's, That's today's thing. That's your, that's your person. I'm gonna get you a folding lawn chair, but it's okay.
But the point is, you know, I mean, by making it so easy to deploy, essentially you are cutting out any kind of adult supervision of that product. And I'm worried that what we're gonna end up with is people just rolling out all of these apps. I mean, you know, we hear about all these privacy data breaches and so on, you know, this, uh, recent one where, um, you know, women's driver's license were exposed to like four chan uh, trolls, uh, you know, things like that.
Well, I bet that that's gonna become a lot more popular in common. Common if some of these ai, uh, driven apps make basic mistakes in their infrastructure configuration and database configuration and security models. Because there is no security model.
It's just sort of like, yep. Ba bing. There we go.
Got yourselves a database. Have fun with that. So we discussed this on yesterday's shows, an article I wrote on, on Security Boulevard, which is the s in vibe coding stands for security.
There is none. Um, but that, that being said, it is the, unfortunately, and I say this as a security person, this isn't new. Whenever something new comes down the pike, security is an afterthought.
Security is a bolt on. Security only gets built in when enough people b***h and moan about it. And so we're not up to the b***h and moan except for Steven.
We're not up to the b******g moan stage Yet. Wait, I'm gonna, I'm gonna defend. Yeah, I'm gonna, I'm gonna back up Steven on this.
'cause I, I had the same impression as like, and when we, you talk about speed getting there, faster, bigger, better, you know, there's always a, a compromise. There's always kind of a, you take a shortcut to something, inevitably there are consequences. And I, I thought about the security hole here.
So I I I, I totally agree, Steve. I mean, we all think about the security hole, but lay yourselves down on the track and see if that train stops for you. I I, my money is, it doesn't, right?
That train's full speed ahead and, and that, you know, as a security person, it's disheartening, but it's, it's what we've seen. We, you know, we saw it with a headlong rush into the cloud. We saw it with, with every new innovation like that.
I, in the article I mentioned 15 years ago, doing a, a podcast with the CEO of MongoDB and Couchbase, and I asked them point blank, there's no sequel, Stanford, no security. And they, and they, and they said, when our customer demands security, we'll build security in. That's what the, the Ceo And has that Happened Because we got so many security breaches.
Yeah, well, in, in no SQL databases, they have put in some security features. It's not as bad as it was 15 years ago. But this, this is the issue.
But, but make no mistake, right? Go west, young man, progress stops for no one. We are gonna see a proliferation of vibe coded apps full speed ahead.
Damn, the torpedoes, right? People are gonna do it 'cause they can. And as a security person, I will tell you, the attitude has to be, we could lay down in front of the tracks and hope the train stops.
That's not a good, uh, strategy. Or we could say, yes, we can. What can we do knowing that this is inevitable?
It's inevitable. What can we do to try to put in some guardrails to try to head it off at the pass, to try to anticipate what's gonna happen here and do something? And, and I think that's the challenge to the security industry is knowing that we're going to, you know, this is like Saturday night, new Year's Eve night, amateur hour, all the, the kitties are drinking and jiving.
What do you do? Are you trying to make me feel better or work worse? No, I'll, but, but this is, this is the reality of it.
What do we do that you're not gonna stop them? The genie's out of the bottle. Well, how, well, here's something I'd like to see.
So this is fricking Microsoft. If there's a company that is mature about software development, it's Microsoft. What I want them to do is I want them to put serious security bonafide days behind this application.
I want them to put some real muscle and say, these things are gonna be deployed properly. They're gonna be deployed with appropriate security frameworks, uh, you know, a real attention to security and stability. And in order to make sure that these things, and and frankly, I think that would sell, people like me would love that.
And people like you probably too. I mean, I can't imagine John's article about, you know, Microsoft promises to integrate security with all their AI coded apps. That'd be a great article, wouldn't it?
John? You wanna Write that one? Yes.
I think, I, I think it would be quite refreshing actually, instead of, instead of an afterthought. I mean, that's with the comment I think Al made about, you know, we'll get, we'll get to it. We'll, we'll address that problem once our customer starts, starts complaining.
I mean, that seems to be the attitude it always has been in Silicon Valley Has been, Maybe rush it out then fix it later. I I was gonna tap into Alan, your, uh, your, your mantra perspective. The trains left the station, right?
This is gonna happen whether we want to or not. It has already happened. I think one unique characteristic of this is people building their own apps, they're probably building it for themselves in a lot of cases.
Maybe they're building it for their business, but if they're building it for themselves, they're putting information about themselves in it, right? Maybe my dog steps, but it could be my investments or something else. And I think that may be an angle to appeal to the market, is if you're building apps for yourself and you want your data protected, we're Apple.
We know how to do that. We're Microsoft, we know how to do that. That's why you want to stay with us.
As opposed to some whatever company that, you know, came out of the, the woodwork to offer the latest greatest. Yeah, that might be interesting. But if you wanna make sure your stuff is protected, we'll make sure your app is built securely.
And, but that's only one angle. It's, it's, it's not gonna stop everyone else from just building whatever apps using a web browser and whatever interface. Security is a day two, day three thing, unfortunately, as much as we'd like it not to be.
And Well, I do have announcement, Alan, I was gonna wait till the end, but since you and Steven were vying for this, uh, I, I think we're gonna establish the Walt Kowalski, uh, grand Torino Award. Get off my lawn award. And this episode goes to, even though it's a second segment, goes to Steven FoST, runner up.
Alan Shimmel, unless you do something in the third segment, I, no, I'm a notable. We have to revisit a notable runner up. All right, look, it is what it is.
Alright, let's take a break. But she Ever says in the movie, by the way, he doesn't say that in the movie. Let's take a break here on the gang.
Kudos to Clint Eastwood. Uh, but let's take a break here on the gang. com is the leading resource for news analysis and education on challenges facing the cybersecurity industry.
com covers all aspects of cybersecurity, including data security, DevSecOps, cloud security, application security, network security, security threats, and more. com has the largest selection of security content featuring breaking news, blog posts, podcasts, and more. com to learn more.
com. Home of security bloggers network. We are back with Textron Gang, and we're gonna talk about a simpler, more focused VMware.
At least that's the, that's the intent. So one of the benefits, ev evidently, of what VMware is trying to do is simplify their product lineup. And, and, and the, so there's less variation across customers.
Everyone's gonna be licensed for the entire VMware Cloud Foundation Suite, rather than making these a la carte purchases of combinations as was standard in the past. So I'm gonna throw it to, to Steven and ask him about this approach. And I gather the idea is large customers would then be using the top of the range VCF, that would be the focus, I guess, from the company and what they're trying to do.
I leave it up to you. Yeah, absolutely. And, and we talked about this last Tuesday on the Textron gang as well, that essentially, uh, as we, as they said they were going to, Broadcom has focused VMware on VMware Cloud Foundation and has simplified everything.
Now, that is remarkable. Those of us who've been in the space for a long time know how insanely complicated and confusing the VMware product lineup and licensing lineup was previously. Well, now it's pretty darn straightforward.
And I actually really like this idea that essentially, look, you're going all in on VCF, we are going all in on you essentially. You know, you're, you're, you're our kind of customer. You're doing our kind of thing.
So we're gonna build a product that is everything you want it to be and give you everything of that product. It's the opposite of the, the legendary, like BMW heated seats, uh, subscription fee. You know what I mean?
This is basically, look, you know, if you're gonna, if you're gonna use our product and if you're gonna standardize on our product, then we're gonna give you everything and let you do everything with it, which is pretty cool. And, um, I've had the opportunity to be part of the recording of the Techron Tech Field Day event that's actually happening right now. And, uh, as soon as you're done listening to this, I urge you to check it out.
It's, it's available as well, um, uh, sort of post viewing if, if, if you miss any part of it. But essentially that's what VMware has done with VCF, is that they have built this thing, they stripped out a lot. Yes, they've stripped out customers, they've stripped out features, they've stripped out capabilities, uh, huge licensing SKUs.
And what, what remains is essentially a purpose built, uh, private cloud for large enterprise. And, you know, this thing is pretty impressive. I, I don't know if y'all have, have checked it out.
Any, anybody else be involved in this? And what do you think of this VCF nine trend? I I, I'm sorry again, Mitch, to jump in on this, you know, when I, I took over, uh, IT organization in 2010, and one of the initial things I wanted to do is how can we put our, our VMware infrastructure on a website or have something where it's self-service?
And so we're, this is that realization of that, where now it's platform engineers, developers, you can even integrate Argo CD to do GI ops on this new platform, the VCF platform. So I, I think it's a very smart move by, by Broadcom to be able to say, stay home. You don't need to leave the town, the state, the country.
You can stay right where you are and you'll get what you want that you can get from a cloud provider on your own infrastructure, um, to try to, you know, I would say stave off moving or for those that said, it's too, too costly or too difficult to move. I really don't have to move off of VMware now. And that simplification of the product screw, uh, SKUs, excuse me, Freudian slipped there.
The, the, all of the SKUs that they had were just ungodly. It was like tracking Microsoft SKUs. It was, it was a beast to figure out what you gotta pay for and keep your cost down.
And, and it's funny 'cause people like to criticize Broadcom and say, oh, they're just extracting money from the customer. How's, how was the million different licensing SKUs any different, right? Well, the, the, the price did raise, let's face it.
But, but let's be clear, it's not just, you don't have to leave. You could stay here. You could take it with you too.
If you want to go to the public cloud, this plays really well. And they, and they talk about their relationships with AWS and Microsoft and Google for, you know, taking, taking, uh, cloud Foundation nine up there. So, and, and especially when we live in a hybrid multi-cloud world where I don't wanna run one thing on my private cloud here or in my data center and run something else there and something else here, and I gotta learn three different things, right?
I want, I wanna standardize. I, I just want to quickly come back to the fact that, hey, if you are watching this right now, we're gonna end in three or four minutes. Head on over.
com. And from there it's the, the first thing right on the screen. You could click through register for free and get right on there.
You probably only miss the first session. And what's nice is all of these sessions are available on demand. You can watch 'em in whatever order you want, actually.
So head on over to Techstrong events, click through, watch this. If you're watching this on our text, drunk TV broadcast, obviously, which goes off, uh, Tuesday morning at 9:30 AM and it's about 10:00 AM now 10 after. Um, but you know, it is available fully on demand.
com, register and watch it on your time. You won't be able to ask questions and interact with some of the speakers and everything, but you'll still get the benefits. Steven, what are there, five or six, I think different sessions here.
Yeah. Um, yeah, so there's, as you mentioned, the first section is sort of the overall what's new session. Um, then there's, um, you know, back best practices for deploying, uh, VCF, um, uh, more about the private cloud on demand stuff.
As, as Mitch mentioned, um, you know, the shift toward self-service, um, platform for developing applications. Um, my favorite, uh, unpacking storage, uh, all about storage in VCF and then finally, um, security and resilience. So, uh, all those different Questions.
Again, last, last, You know, finally it's included. I, I have a question before we go. Am I the only one questioning?
Um, since, uh, there is a good number of the product management team that stayed with Broadcom, uh, after the move and the acquisition is I'm, am I the only one that's questioning the leadership of VMware and not being able to, like the, if product manager was able to come up with this on the Broadcom, they must have had these ideas on the VMware and would, we're not friction between product. I don't wanna talk outta school, but you know, jp, that is a hundred percent correct. There were people at VMware saying this, uh, well before Broadcom was sniffing around the company.
Yeah. But sometimes it takes change to, to accept change, right? And yeah, that's all true.
But you gotta give, I, I think I wrote this on a social media post or, or in the article, I wrote a couple of articles on this. You know what, for all those people who gave Broadcom grief that this was the death of VMware and this was going to make a mass exodus, exodus from VMware hang, and the Broadcom people are crazy like a Fox. They, they, they saw this had to be done and they got it done.
I applaud them for it. Um, head over to Techstrong events and check it out. Be your own judge.
Don't listen to any of us pundits. Um, That's probably good Advice generally. Yeah.
Um, all right. Hey, I think that's gonna wrap us up here today for Tuesday's Techstrong Gang. I'm gonna be on the road tomorrow.
John and Mitch are, are driving the bus, and, uh, they'll keep it. I'm sure they'll do a great job. Jp, Steven, John, Mitch, thanks for joining us.
Thank you for joining us. You could watch the rest of Techstrong tv, but I'm telling you, go over to Techstrong Events and go watch the Broadcom event. Until next time, this is Alan for Techstrong.
We're out. Hey everyone. Welcome back here to Techstrong tv.
I've got a first time guest here on Techstrong tv. I always enjoy meeting new people and hearing, hearing their story. This is a great story.
I think you're gonna like it. Let me introduce you to Rab Geary. Rab is kind of the newly minted, let's say, chief product and technology officer at a company called Voltage Park.
If you haven't heard of Voltage Park, don't worry, we're gonna tell you all about them. But first, let's hear all about Rab Rab. Welcome to Techstrong tv.
It's great to have you on here, Alan. It's a pleasure. So let me do a very, very quick intro.
Like you said, I'm relatively new in my role here at T Park. I lead product and engineering. Um, I joined Voltage Park in Marsh, so call it five months.
And then, uh, before Voltage Park, I was at Amazon where I was part of the team that built and operated Amazon's platform for generator ai. Your reader's map heard of it, is called Amazon Bedrock. And then before that, sure, I was a failed entrepreneur.
I tried twice. And then before the third time, I decided to join a place like Amazon and learn what Amazon knows. And when I was done learning, um, I moved on.
Excellent. You know what they say that you learn more from your failures than you do from your successes. And you wouldn't have been successful I bet, at AWS and m, you know, a w and with Bedrock without some of the lessons you probably learned as an entrepreneur.
Absolutely. And you know, I, I, uh, Brad, my friend Brad Feld is pretty well known VC person and he taught me that. And unfortunately, I also have had my share of failures and successors, you know, usually with other people's money, thank God.
But you know, we, we do learn from them anyway. I think most of our audience, sir Rob knows they've heard of Bedrock, a lot of the audience. 'cause everybody today is AI savvy.
A lot of the audience has, uh, heard of and knows more than just hearing of they know about Bedrock. But there are some people out here who don't. Well, it's not the focus of our discussion today.
Sirah, you mentioned it's the AWS platform, but it's so much, you know, there's so much more behind that. If you wouldn't mind, take a minute, a minute and a half, give us what Bedrock really is. So Bedrock broke new ground in many ways, and I'm really proud of what the Bedrock team was able to accomplish very, very quickly.
One way where it broke ground was it called out correctly that at some point every company will need to interact with more than one foundational model because there's no one model that is perfect for every use case. It's always going to be a number of models. And what Bedrock provided to the enterprise world was an abstraction where you can write software, you can integrate your workflows and your software using an API.
That abstracts are where the complexity of what the model is behind the scenes, it abstracts a where the modality doesn't matter. It's a text model multimodal model. It's the same API.
And that was, uh, how Bedrock was, um, early to, to that particular vision. And that vision has only proved itself more with time. There's no one model that is perfect.
Companies will need to learn how to interact with the multitude of models, the right one for Hs case. Great, a great description and thank you. So Rob, if you wouldn't mind, I'd like to turn to Voltage Park.
I am, I don't know a lot about Voltage Park, and I'm pretty sure our cust our people watching our, our base here, our community is also not as familiar with Voltage Park. If you wouldn't mind, spend some time. Absolutely.
Who is Voltage Park? What do you guys do? So Voltage Park said simply is a cloud service provider that specializes in AI workloads.
It is a startup. We were, we were founded in 2023. Today we have six data centers in the US two offices, and our f footprints rapidly growing.
We are one of very few people in the US that actually owns GPUs. So we are one of the few people that owns GPUs at scale. And we, um, we serve, so in, in the Bay area, if you're driving down 1 0 1 freeway, you will see billboards, you will see billboards of companies that everybody knows about, right?
Sure. What is not well known is a lot of those billboards are on Voltage Park. They are my customers.
And what we do for them is give them world class hardware and we give them the, um, the velocity of a startup because all of these customers are pushing the edge. They're pushing the edge on, um, on basically what GPUs can do. And at that edge, you need somebody who can move at your velocity.
So we are able to move at their velocity. We are a startup. We have, uh, some of the best engineers in the world, and we give really good hardware.
And we do this all at very, very reasonable price performance. Now, if you segue that slightly into, um, this sounds familiar, many people do it. Um, what are, in what way are we different?
One way we are different is, um, voltage Park is a mission-driven company. So we were, we were founded on the, on the hypothesis that AI compute, which actually, so December, 2022 was when Chad GPT had the world. And then by January it had the imagination.
It went to a hundred million customers. It was the fastest consumer product, right? And then back then, um, the thing was, this AI thing is real, but to do anything with ai, you need access to compute.
And it was not easy back then for people to actually get access to compute for researchers, for startups to get access to compute. So we were founded on the hypothesis that we would democratize access to compute. And, um, in the two years since then, we've expanded our mission.
Our mission is to democratize access to ai, not just compute. And the difference between the two is to do useful things. With ai, it's more than hardware.
You also need software that allows you to use this extremely expensive asset efficiently. So that is our mission today, and that is where, that is why some of the billboards, um, on 1, 1 0 1 freeway in San Francisco are with us. We do that.
Well, I love it. You know, it's interesting. I think for a large part of our audience, they have a very binary view of where they host their infrastructure or what infrastructure they run on.
If it's a public cloud, it's AWS maybe Google or maybe Microsoft there, maybe some of them are in Oracle, but if it's not one of those, then it's sort of a, a private data center and it's their own infrastructure and it's, you know, their own thing. We haven't seen a new competitor come on the block that's offering this type of, of offering. And, and granted, it's, it's, it's not for everyone, right?
But if you, if you, if AI is your thing, GPU acts, you know, access is your, is your thing. Voltage Park is every bit a competitor of, of the big three is, is that fair to say? So, um, I want to approach this with the humility of 10 years from now.
Some things will be inva 10 years from now, the three hyperscalers will still be there. Absolutely. They have a useful role in the world, and they're all good in their own way.
And then 10 years from now, the four AI labs will be there. The four are, um, so I'm talking about the foundational model providers. So o Open ai, open Ai, Andro, quad, yes, Claude, and then Google, uh, Google's, Gemini, Gini, And then, uh, XAI.
These are extremely well capitalized companies, and their models are already excellent. They have crossed the point of they will be here and maybe, So they're foundational. What do you think about deep seek?
Deep seek is interesting in a different way. You really have to think of deep seek as an abstraction for open source. Now, deep seek in itself, deep seek in itself is maybe, maybe not what US companies will use at scale, but deep seek was mind blowing.
I actually wrote a, uh, I wrote a memo like one year back, back then deep seek did not exist, but I called it out. And, um, this actually is a good segue to something else I wanted to hit on. Um, but, but, but, but let's close the thread and then I'll, uh, take this segue.
Sure. So deep seek is an abstraction into what is the role of closed source models and open source models. And today it is deep seeq, but deeps seek is not the only one.
There's a lot of Chinese companies that today are pumping out extremely excellent models. And, um, they, they're really good actually. And in the US Lama used to lead that charge.
Um, but um, but right now the open source ecosystem is still evolving. My view is that 10 years from now, open source will have a much, much bigger footprint than it does today. And to me, that is a foundational invariant.
Yeah, I don't disagree. I I I don't, you know, though, it's the new thing. I don't think it's gonna be very different than our software world today where open source is, you know, a, a major player.
It, it, it's some say dominant. I don't know if it'll be dominant in ai. As you said, the four foundational models have a, a huge headstart.
And the capital is the thing that's different about AI than just regular software, I think is the bar to entry is very high when it comes to dollars. The amount of money that these four foundational models have, you know, have access to makes it very hard for just a, an open, and I, I don't mean to say it in a bad way, but just for an open source project to try to compete at that level. When you're up against that kind of capitalization though, look, you know, deep seek I think was a bit of a Sputnik moment, right?
If you will. So I, I'd love to challenge you, um, in one respect. So there's a very big difference between what it takes to build a frontier model.
Yeah. Frontier model is literally pushing the edge. Frontier model is, um, uh, again, the word is, uh, controversial, but frontier model is what gets us to super intelligence.
You are right that to get to super intelligence, to be a frontier model, you need the capital of the four labs. Uh, it's not that easy for someone to just do it. You're right on that.
But then, uh, empirically it is also a fact that somehow, somehow there are open source models today that are actually quite excellent. Now, they may not be the frontier model, but then you get into, in daily life, do you really need a loor for everything you do? You're dropping your kids to school, you're going to buy groceries.
Honda Civic is better, right? You don't need to have a lamborgini for everything. And I also absolutely, I also want to make a different analogy.
Um, for those of us who are old enough who actually lived through the nineties, I think the, um, generative AI landscape today has extremely interesting parallels to what was happening in 1991. So if you replay back to that moment, by the eighties, Unix was a thing. It was a real thing.
And it was no longer mainframes. Unix was a credible alternative and useful in addition to mainframes. And then in 1991, what happened?
So there was Unix, there was this guy li uh, Lin. So somehow he figured out how to, uh, make a variant of Unix and make it work on commodity hardware. And then what happened in 1991 is the whole thing exploded.
If you wanted some simple use cases like a mail server or so many other use cases, you do not have to pay tens of millions of dollars to stand up something very expensive. So today, the generator AI world is exactly like that. You can go to hugging face the thousands of models.
If you, if you know what to do, if you are a developer, if you know what to do, then it's a extremely exciting moment for ideation. My high school kid, he can do things from hugging face that I had not imagined possible two years back. Right?
But what is missing in this whole landscape today? What is missing is enterprises. Enterprises has been a disappointment for the whole industry.
So 2023 was the consumer moment. 2024 was supposed to be, when enterprises depend, 2025 was supposed to be when agents and enterprises will go full on into production. That did not happen.
So today it is still similar to 19 92, 19 93 in a sense that for enterprises, they have a cold start problem. Cold start problem means where to start. Do you, do you lock in on one of the model providers?
That's confusing because every two weeks the leaderboard changes. Do you lock in on one of the hyperscalers that sophisticated enterprises have? PTSD, they don't want to lock in just yet, right?
1995, red Hat was born. What did Red Hat do? Red Hat simplified this all and said that we will take a opinionated view on what is the optimal stack to use for various use cases.
They gave enterprise support, they gave one phone number, anything goes wrong, you call that one phone number. And that is what changed it for enterprises. So one analogy that I would like to offer is, the reason I, John Voltage Bar is we are aspiring to be the red hat of Generator bi, where we will eliminate the Cold Start problem.
And we already are. Uh, we already are, we have traction. So that is our mission, that's why Kim, I love it.
What a great, what a great way of, we wanna be the Red Hat for Gen ai. So Rob, I, we, we don't have a lot of time, but I wanted to talk a little, just one more area maybe we could talk on, uh, we're gonna need to continue this conversation, but for now, we mentioned, we were talking off camera about this term AI factory. I like it.
I I also use the term software factory where platform engineering and DevOps and SRE and you know, they, the cloud native, they all are different parts of this, this factory, different aspects of the factory that allow us to develop software today. I think there's a similar thing to the AI factory. There is the GPUs, the hardware, there's the storage though, there's the software, there's the whole ecosystem that's needed if we're going to, if we are going to get enterprise grade AI working, right?
It, it doesn't exist in a vacuum, but yet some people push back on the idea of a factory. It sounds, I, I don't know, it sounds too blue collar to them. It sounds too mundane.
I I'm not even sure why, excuse me. You know, but you, you, you run into this, I'm sure at Bedrock at AWS with Bedrock and, um, you know, I'm sure at Voltage Park, you guys have discussed it. What, what is it about the term AI factory that evokes both good and bad In, in people?
So, uh, by the way, I fully sympathize, um, with that reaction to AI factory. I did not invent the word. I think it was first publicized by Nvidia.
And, um, the reason it evokes that reaction is it simultaneously means nothing. It's a marketing term and it could mean anything. So no one really knows what it is.
But I can tell you my interpretation of what it is. So to hear Jensen describe it, which I actually agree with, um, someday AI will be like electricity as in you don't think about it. You just plug in, you use it, it's not there yet.
It'll be there. And then the way Jensen says it, which which also agree, AI Factory is simply a place where companies can manufacture intelligence out of data. And I will explain this.
So a physical factory, you have capital, you have machines, you have software, you have people, AI factory needs three things. You need the hardware. And as you mentioned, it's GPUs, it's storage, it's networking, it's all of that you need a software stack to consume the hardware, and then you need models.
There's only three things you need. And then from a enterprise's perspective, um, they would rather not care about the details of these things. All they want is in the real world.
They have actual processes, they have actual products. How can they tap into what AI can do? And as a concrete example of what we are actually doing for one of the three governments in the Middle East, they came to us with exactly this.
They came to us with, they want to start with a real world use case. And they don't want to buy into the hype. They want to prove that the AI is useful, and they want a way to scale from nothing to how much of meaning infinity.
And they want to do this in a way where they don't care about the details. So our vision for AI factory, unlike the prevailing vision today, is you don't have to spend tens of millions of dollars to put, stand up this capability and then figure out what to do with it. Because then boards lose faith, management lose faith, and it is very wasteful.
So we will abstract away the complexity of all of that. We will show up with a model that actually works for a real world use case. You don't have to care how it's working.
And this thing can scale from nothing to how much over you want. And plus, love it. Sarrah, I I could probably talk to you for two or three hours and scratch the surface, but unfortunately we're, we're outta time here.
Let me, first of all, congratulations to Voltage Park for landing you as the chief product and technology officer, but congratulations to you, you know, moving from one at, uh, step in your career at AWS into now back into the startup world, right into the entrepreneurial world. I'm sure you're gonna be much more successful this time. Um, secondly, come back.
Let's continue this conversation. This is a conversation that our audience wants to hear too. So let's make plans to talk some more.
Um, good luck. I I know you've got some traveling coming up, but good luck on that. Safe travels, and we will talk again.
Thank you. Thank you so much, Alan. It was my pleasure, Sir.
Rob Geary, chief product and technology officer here at, uh, at Voltage Park here on Techron tv. We're gonna take a break on Te Techron. We'll be right back in a moment.
Hello and welcome to the latest edition of the digital CXO Leadership Insight series. I'm your host, Mike Bazaar. Today we're with Yano.
Well, Linda, who is CEO for Kraft Ful, and they were just acquired by a company called Amplitude. And we're talking about the two of them together or analyzing data. And on one side.
And then the other side of it is, um, Janna's company is collecting the data and getting the feedback in the first place and understanding what people are trying to, uh, say. It's not just a matter of data, it's also understanding their intent. Yana, welcome the show.
Thanks so much for having me, Mike. Really excited to be here and, and talk about this stuff. Yeah, I'm not sure most people know who both companies are.
So walk us through what's the motivation for this merger and acquisition and how it all came together? Yeah, absolutely. Um, so for on, on our end, obviously, we, uh, on, on the craft full side, we help over 60,000 product team listen to users at scale by collecting user feedback from all these different sources of support tickets, call transcripts, survey data, app reviews, and make sense of it all.
Um, amplitude is this incredible, um, broader platform that really helps teams build better products by providing product analytics, but also things like, um, session replace surveys, um, AB testing, really a whole, um, tool set of different, uh, ways to help product teams be, be more, uh, successful building products. And so the missing piece to, to the puzzle on their end was really to be able to understand what users were saying and find that needle in the haystack, and that's what Raffel does. Um, so we ended up chatting with a team.
We talked about a few different ways to partner together, but ultimately as, as the, uh, as the Amplitude CPO told me was we should just be one team. And so, and so we started talk, talking about, uh, joining forces and becoming one team. And, and, uh, and it's been an incredible conversation so far, and ultimately we ended up joining them.
Mm-hmm. What is challenging about understanding what end users are trying to say? You would think that they just fill out a form and everybody could figure it out, but I'm sure there are nuances in there.
So what exactly are we surfacing? Yeah, so the big challenge is really the volume of feedback that, that every company gets. And my, my background is I've, I've led product at various companies, everything from being PM number two at a, at a fast coin unicorn to leading product team with, uh, where, you know, our products were used by millions of users.
And the challenge is really that you're getting a ton of support tickets every day. You're, you, you sales team has a bunch of calls with, with customers, uh, if you're a mobile app or if you're some sort of like online product, you also have online reviews or mobile reviews and you have survey data. And so what what ends up happening is that a lot of this feedback either gets ignored or you have teams spending lots and lots, you know, hundreds of hours trying to analyze all this data and make sense of it all and try to incorporate it into the product team's development process.
So what we ended up doing is really saving teams hundreds of hours, um, and instantly telling you, here's your list of feature requests that are coming from all of these different sources. Here's what, here's the feedback you got today, and here's the actionable list of things that people are asking for. And then you click through and see what exactly people said and, and, and turn that into, um, tickets that your engineers can start working on immediately.
But it's, it's sort of like making sense of it all. Mm-hmm. We are, of course, living in the age of AI and we're all obsessed with data.
Um, as the two companies come together, are there ways to think about applying AI to the analysis that will help people maybe surface some more interesting insights? Absolutely. Well, craft is an AI native platform, and I should say a large language model, native platform.
So we have our proprietary LLM process that we apply to all this data to, to turn it into actionable product insights. So that's kind of our better, better is to really use AI in, in all of product development. Um, and Amplitude on their end have already started the journey of, uh, really building out different AI capabilities in, in different, uh, products.
And so now we're really bringing all of that together, um, and making sure that we're building the platform in a way that's thoughtfully applying AI instead of just bolting it all on onto an existing product, which I think a lot of teams do. Mm-hmm. So what is the ultimate impact on product managers and the people who are trying to decide what the next product to build is?
Um, will they take all this data and make better decisions? 'cause a, a lot of times I feel like they're always wrestling between, uh, um, instinct and data. That's right.
Yeah. So absolutely. I think, I think the key is really understanding everything that users are doing and saying, and that's, that's what the joints, amplitude Craft will experience is gonna provide.
And then it is up to product teams, um, to then decide what to do with that. Um, and a lot at that point, a lot of that is product intuition and being able to make thoughtful decisions. But if you don't have the underlying data to even make those decisions, then you are acting on instinct.
And that instinct is often, uh, misguided, right? It's not, it's not based on anything that users are, are actually interested in. Um, so we are really making sure that you have the relevant data points to then use your intuition in, in the, in, in the best possible way.
Mm-hmm. And can I experiment more readily? Because maybe I can segment different, uh, types of people that might be using my product for different use cases, and as such, I might discover entirely new use cases for something Absolutely right.
You can, you can, you can segment better, you can survey users better. You can in moments understand if something is appealing to your users, um, and sort of, uh, act much faster on, on different hypotheses that you are also forming based off of all of this data that you're getting. So there's so many different ways in which you can, you can faster iterate in the process.
Are the teams themselves going to become more integrated? And I asked this question because a lot of times when I see folks who are doing data analytics, they're often their own little group somewhere, and they don't always interact so well with the folks in manufacturing and sales, et cetera. So are we gonna get, uh, better able to kind of take all this data and surface something that feels like more actionable intelligence across those teams?
Absolutely. I think, you know, one, one thing that we've thought a lot about is bringing in insights from, uh, data sources that product teams didn't have to or haven't traditionally taken into account. And by doing that, by listening to customers in, from sales calls and getting insights from those conversations and getting insights from conversations from, uh, support ticket channels and all of these different channels that product teams traditionally haven't necessarily listened to, uh, product teams are building empathy not only with the end users in those specific situations, but also with their colleagues that are having to respond to, to those requests for having to pitch the product in a sales meeting.
Right? So I think that does make the whole team a little bit more interconnected, um, in ways that, um, that hasn't been possible before, just because the volumes have been so large that no one's really tried to take that on. So who in these organizations kinda wakes up one morning and has the aha moment that says we need to rethink analytics and, and drives this kinda investment?
Yeah, so it's primarily gonna be product managers, um, in, in, um, in folks within product teams, product and engineering team. So it goes a little bit broader than that, but I would say that the kind of the primary persona is usually the CPO, uh, and, um, and the product team. And that's true, that's true for Amplitude, and that's also been true for crackles.
We had that joint persona, uh, that we've been serving, but with different solutions. And so now we're gonna be serving, serving them jointly in a, in a much more effective way. Mm-hmm.
In the age of ai, how smart will smart get? And today, I feel like a lot of the issues with the analytics is I need to know what question to ask in the first place, but I wonder as I go along here with things like AI agents might not the AI agent know what question to ask before I even think about it. Yeah.
So, you know, one big piece of this is that you shouldn't have to think about what question to ask. Your users should be telling you what's, uh, what they care about. And they already, the good news is that they already are right.
Um, and so this, what this does is just make sure that you can effectively listen to those, uh, to all of the feedback you're getting from users. Um, now we, uh, at Craft will actually have developed a survey method that takes your past feedback into account and builds follow up question for users. Uh, we can do that either, uh, before you set up a survey or proactively in real time while a user is providing feedback.
So it takes the user's prior response and formulates the follow-up question. Um, that's gonna help you dig deeper from, from a product insights perspective. So definitely lots of opportunities to, um, to leverage AI to make sure you, you get to ask the right questions, but it's also just a matter of listening to everything users are already proactively sharing, because there's a lot, there's a lot of insight there.
Mm-hmm. And is all this happening at a higher level of scale? Because in my mind, at least historically, product managers would, you know, they'd get a panel together and they'd stick 10 people in a room and hope for some sort of insight to come outta that.
But whether that was applicable to the entire customer base was anybody's guess. So are we just gonna get smarter about all this? Absolutely.
This, this is a way to make sure we can listen to users at scale. And when I say scale, to give you an example, we had a customer at Craft Full that surveyed users, and they got, uh, they got 16,000. They were able to survey 16,000 users in, uh, in, in just a few days.
Um, and, and incorporate all of the, those insights instantly because they instantly got a list of feature requests and complaints and all the different, uh, topics that users were saying. So that volume is something that hasn't been possible before. As you say, you sort of, you had to listen to a small group of people that wasn't necessarily representative of the user base and had gave you sort of a skewed view on what, uh, users needed from a product.
So what do you see people doing today that just makes you shake your head a little bit and go, folks, we need to just be a tad smarter than that. Um, you know, I think a lot of the, I, I still do see folks do that, you know, focus groups and, um, kind of small scale feedback where you, you could gather just so much more data. Um, and then another thing that I see that, that, that personally irks me is when folks listen to users have a way to collect feedback from users and then dismiss it as sort of like, well, this isn't helpful.
This is just a bunch of people telling me that they need a faster horse. I need to think bigger. You know?
Um, and, and, and as they're thinking bigger, they're not thinking about that car that they could be building for the users that are asking for a faster horse, they're thinking about something completely different, right? Um, that, that isn't at all helpful to what folks are asking for. So I think that, uh, the, the kind of, the, the arrogance in, in, in product teams is the thing that sometimes, uh, it really gets on my nerves, or I'm sort of like, well, you have lots of data.
Why don't you kind of creatively think about what is, what, what is it that, what's the thing that would really help these people be successful? Help your users and customers be successful based on what they've told you? Go, Hey folks, we're all trying to make better data-driven decisions, but, um, frankly, you just need to be able to sort through that data at scale.
And well, AI will hopefully sort all that out for us a little bit, but, uh, maybe we'll just make happier, better customers. Who knows. Hey, Yana, thanks for being on the show.
Thanks so much for having me. Really enjoyed it. All right.
And thank you all for watching the latest episode of the digital CXO Leadership Insights series. You can find this video and others on our website. We invite you to check them all out.
Until then, we'll see you next time. Hey guys, thanks from the throw, we're here with Kai Mitchell, who's president of experienced us, and we're talking about a survey of CIOs they did because, well, we live in highly uncertain times and everybody wants to know what is on the mind of the CI. Kai, welcome the show.
Thank you so much. I'm thrilled to be here. Being the CIO has never been an easy job, but I think it might be a little harder these days than any time in recent memory.
When you looked at the survey, what kinda leapt out at you? You know, I think for me it was really, um, cybersecurity still. Number one, AI adoption is obviously on everybody's mind, but the key takeaway to me was really that no long CIOs are no longer choosing, um, between security innovation, they have to do both.
And the winning strategy is often, you know, integrated, resilient and aligned to real business outcomes. So not a lot of surprises for me, but cyber and AI is certainly top of mind for most, I think when I talk to them. I mean, cybersecurity has always been top of mind, but to your point, they are trying to have their cake and eat too.
But the issue is maybe they don't have all the skills and resources they need to accomplish that mission because, well, there's just not a whole lot of AI expertise, for example. So how are they kind of approaching what they invest in for staffing versus what do they partner with and what do they look for from the vendors? Yeah, so I think ai, like you said, a lot of people don't know it.
It's new to a lot of folks, but I think the ones who are, the people who are gonna stay relevant are really leaning into it, learning it, um, and they're bringing it through everything they're doing. So for us, for example, experius Does is a global technology, um, talent and services provider. And we're really trying to take AI and implement it across the board.
So bringing into automating coding, bringing it into, um, automate testing and, and not just be a standalone issue, but how can we integrate it into everything we do? And in doing so, we are able to help them do more with less, more quickly and those types of things. So for us, what we're trying to do is, we've got a few real experts.
Um, hir Ahan for example, leads my, um, ai, COE, and those experts are training our people on the job. We put an expert on with them, they train 'em, they ramp 'em, and they help pull it through everything that we're doing for our customers projects. I think a lot of customers too, were talking about looking at how are we changing, um, what our folks are focused on.
So for example, training people in prompt engineering, training them in various tools they can use. And so training and upskilling is an important part of it as well. Mm-hmm.
I think there's also some nuance in all of this in the sense that there are things that need to be done, but they only need to be done maybe once or twice. And then there are things that the IT team needs to do every day. And I think distinguishing between those things is important.
'cause that helps you decide, well, what am I gonna give to a partner to do maybe for us once versus skill that I gotta have in-house? Yes. I think that's very true.
Um, so a lot of times they'll come to us and talk to us about doing a specific project or for example, coming in, helping them get their data optimized so that their data is structured properly, it's clean, and then they're able to apply AI to it. And so they might come to somebody like an experius to do that, um, because it is that one time thing, and then they'll have their folks go ahead and operationalize it, continue keeping it going. Um, but I think also too, a lot of companies don't have, um, those skill sets right now.
And so they're also coming to us for thought leadership and what are we seeing in the marketplace and, um, how are other companies doing it? Um, for us, when it comes to ai, I've really found it's a show not tell type scenario, which is very different from other phases I've been in in my long career in technology. And customers are really looking, even for us to show 'em how we're applying it internally to how we do business to help give that credibility that yes, we can help 'em in that partnership.
Um, and, and then also talking to them about how we have taken our best and brightest and upscale them. But 76% of tech employers feel it's a real struggle still to find skilled talent. Mm-hmm.
Do you think that there's a newfound respect for data management because of ai? I mean, we've always kinda, uh, dealt with data management, but it, it was uneven at best. And certainly, you know, more I'm focused on structured than unstructured data.
And when I go talk to people, they're like, you know, wow, we got all excited about AI and then we spent the next nine months working on data management issues. So is that, you know, kind of where we are? Yes, for sure.
I think it's really opening people's eyes. I think, I think for a long time we've been looking at the value of a lot of companies is in their data, but between AI and also cloud, you know, what we're seeing a lot in the shift to cloud engineering. Um, people have moved to the cloud, but the cost of the cloud is so expensive.
If your data is not properly aggregated, if it's not, if, if you aren't continually looking to optimize how much it takes up in the cloud, you know, so folks are coming to us and talking to us not just about data in the AI space, but how do they get the most out of their data? How can they optimize it so they aren't having to spend as much on cloud storage and those types of things. So it's really going across multiple avenues.
You know, the other thing that I'm seeing is that CIOs are getting involved at a specific point in time. And historically, if I look at some of these AI projects, they were led by a Special Tiger team was created and somebody was managing the infrastructure for that one team. But as we try to do this stuff at scale, and we have multiple projects, it feels like more CIOs are getting involved because they have to manage infrastructure that's gonna be shared across multiple projects, and they have that expertise.
So have we reached some sort of, uh, seminal point here where that's what's getting it folks more involved? Yes, I think a hundred percent. Um, it's interesting, when we did our survey, only 13% of the CIOs we interviewed considered it a top CIO responsibility right now.
So I do think they are still having some of those Tiger teams. But where CIOs are really focused is the ethical implications, the transparency, the realistic ROI from AI tools. So I think CIOs, you know it, in a lot of places, it's gone beyond proof of concept, and now it's about proof of value.
And those CIOs are really focused on, again, you know, are we getting the ROI do we have, are we considering all the ethical impli, uh, implications? And, um, 36% still say, though it's unclear, um, what the answers to those types of questions are going to be. Mm-hmm.
I seem to remember going back in time a couple of decades, that it was a while they were, CIOs were, you know, they wanted to be on the board, they wanted to help drive the business strategy, and maybe they got a little bit away from the core technologies. And now it seems to me you really need both. You gotta have some business acumen and you gotta understand the tech deeply, or you're just not gonna win the game.
Yeah, I, I totally agree. I think technology is not just a support function anymore, it's really a business driver. And so they have to continue to really, um, drill in.
And in that CIRO organization, a lot of times even you're looking at CTOs and CISOs and how, and having it even segmented further. Um, chief digital officers, I think, I haven't run into customers yet that have chief AI officers, but I think you're gonna start to see, we have chief data officers, we have all those things there, enough folding under that umbrella. Um, but I really do think it that technology is such an important part of accelerating business that CIOs, you know, need to as seat at the table.
Hmm. Are there too many C-level tiles running around these days? 'cause sometimes when I go talk to these people, it's like, well, there's nine committees and nothing gets done because all it takes is for one of them to say no.
I do think it, I, I do see a lot of that. I do see a lot of that from time to time, but I think companies, um, are really starting to get more lean and really get after, um, how do we move more quickly? I do think folks know that if they don't adopt quickly, their strategies are going to be at risk.
And so they're really trying to get tech deployments out more quickly. And they're, and I think another piece of it that's really come to light is, is user adoption. You know, how do we think about getting our users to use this?
And it's not just the CIO pushing something out, but how do we get the business on board and get them aligned to adopt it? Mm-hmm. Um, we talked about cybersecurity early on, and historically, you know, cybersecurity's always been an afterthought.
We kind of go build something, run it out there, and then we all go, oh my God, it's not secure. Are we getting any better at that with ai or is it gonna be that same cycle again where we're gonna roll out a bunch of AI stuff and then marvel at the fact that it's not secure? I think that's why the CIO role, the CISO role is so important in IT today.
I mean, we have to look at how do you still keep it secure? And so I think that's why they are bringing in CIOs to look at it more, more closely. You have to make sure, you know, and that's where we're seeing a shift too.
You know, it's not just app dev anymore, it's DevSecOps and how do you bring security into everything you're doing? And that'll continue as you're bringing AI in to do more automation and things. You have to think about what is that secure environment and how do companies protect themselves?
So I think se si, I think security cyber is still front and center of most boards minds, and it's, it has to go hand in hand with how we're thinking about AI as well. So as you look at the survey and your own personal experiences, what is it that one thing that you wish CIOs would think a little bit more about before they go running off and funding various projects? Uh, that's a really good question.
I think, um, I think also continuing to think about human first when it comes to these things, technology alone won't solve it. We need to be human first as we're thinking about ai. We need to be human first as we're thinking about cyber.
And I think really, you know, how do we adopt AI thoughtfully with, you know, good ethics, good governance frameworks. Um, and it's interesting too, 'cause with ai, we're also having to partner more with HR because there's a lot of different rules and things coming out about how you can use AI in your hiring, um, process. And so I think we're gonna continue to see redesign of IT roles for ai, for cross-functional flexibility.
I think you're going to continue to really see, um, soft skills and empathy alongside where technology is going. Mm-hmm. And to your point, I, I think CIOs are trying to navigate a, a difficult issue where the business side of the house thinks that AI is here and all the magic should happen tomorrow.
And, you know, they read all this great stuff and then they go back to their IT people who say, well, yes, but, and then it requires time and effort and money. And then there's conversations about ROI. Um, what is your best advice to CIOs to help them kind of navigate that pressure?
Because otherwise, you know, on the one hand, they want to be viewed as being enthusiastic, but they're also the realistic kind of make all this stuff happen. Yeah, I mean, it's a, it's a tough position that I think CIOs find themselves in today. But again, I think, you know, they have to really tackle that internal resistance with clear communication, realistic rollouts.
I think it's also, um, looking at what makes most sense and, and, and very much measuring, here's, here's where we have ease of doing business. Here's where maybe we can improve productivity, but here's where it is continual things that we can automate, that we can make easier and, and more flexible in our business. But it takes partnership from the business, from your different C-level roles, you know, C-H-R-O-C-F-O, all of 'em, to look at it to help prioritize the areas to attack first and to help make sure it's being adopted and, um, and doing what they intended to do.
All right. Hey, folks, back in the day, CIO, they used to joke, it stood for career is Over. I'm like, now that CIO stands for career and Overdrive, because it turns out CIOs are now at the center of this conversation, especially around ai.
So buckle up, it's gonna be an interesting couple of years. Kai, thanks for being on the show. Thank you so much.
I appreciate you inviting me. All right, and back to you guys in the studio. Hey everyone, it's Alan Shimel, founder editor-in-chief of Techron Group.
Welcome to our second video in a series we've done with our good friends at Adobe. Looking at the influence, the impact of AI and security. I've spoken to five different Adobe security professionals.
In this next video series, you're gonna watch about how Adobe themselves are using AI to make their security more effective to make the Adobe products you use more secure. The beauty of this, it's not just about making Adobe more secure, but there are lessons here for everyone in how do you use and leverage AI to make security more secure. And my first guest in in this series is Brian Payne, who's Adobe's VP of product and software security, and he's gonna give us a little bit more of an overview of the work his teams are doing in AI and security.
And welcome back to our continuing series, discussing Software Insecurity with our good friends at Adobe. My guest for this episode is Brian Payne. Brian is the VP of product and software security at Adobe.
And let's welcome him. Hey, Brian, how are you? Doing well, thank you.
Thanks for coming on here. Brian, VP product and software security. Sounds like an awesome job, but tell us a little bit about kind of your journey and how you view your role.
Sure, absolutely. So my role here at Adobe is to oversee the security of all the software we produce, and that's our products and all of our in-house software tools as well. Um, and I'd say, you know, I got here throughout my career just focusing on security and software over the years.
Um, I've been with the government, I've been in academia doing research, and, uh, spent the last 15 years or so in the private sector here, Brian, of of course, we've, you know, we've entered into the age of ai. Sounds like a, an old song. It's not Aquarius though.
Um, and it, you know, whether you buy into the whole AI hype or not, it certainly is changing the way things are being done here, you know, from in every aspect. It, it promises all kinds of disruptions. Um, and, and ai, quite frankly, to those of us in the security world, it, it's kind of a shield and a sword, if you will.
Right? Unfortunately, it is for the bad guys too, you know, that's always the case in security. Um, so, but you know, the topic of our short discussion today is maximizing opportunities as well as minimizing risk ways to leverage AI for security.
If you wouldn't mind, again, without giving up trade secrets, or let's not get us ourselves in trouble, talk to us about, you know, lessons learned at Adobe, some of the things you're doing, some of the things you're trying, some of the things you're thinking about along these lines. Yeah, so you're absolutely right that AI can be used by, by anyone. Uh, it's a tool and you can use tools for, for good and for bad.
And I think, you know, in the security world, we're keenly aware of that, that history, that's always been the case with tools. And so, um, one of the things that I see is that it's important for us to, uh, be able to understand how to use them and stay ahead of the curve so that, uh, the, the attackers are not getting the edge right. Um, at the end of the day, we find that it's very useful to help us scale.
Um, I've rarely run into a security person who just feels like they have so much extra time in the day. Um, and so, so the ability to, um, take care of some contextual generation, uh, help us learn faster, help us get to the key points faster, and then let people do what they're best at, right? Using their brains to solve those security problems, um, that's really the key for us.
And, uh, and it comes out in many, many ways throughout our work. So if you don't mind, Brian, let's, if we could dive, peel that onion back a layer or two, how, how does this manifest itself? What are some of the ways you're leveraging ai?
You know, we look at different code bases all the time. If you think about the number of software projects happening at Adobe, it's a common thing where a security engineer needs to look at a code base that they've never seen before, and then come up with an assessment of what security work might need to happen around that code base to make it even stronger. And, um, that can be a challenging pro process to wrap your head around this, but AI has proven very useful.
Um, you can just ask at things like, what end points are gonna stand up when I start this code base, right? Uh, which functions receive untrusted user input? Um, it can help you navigate the code in a way that gets you to a destination much more quickly, um, which is fantastic.
It doesn't mean that it's, it's necessarily replacing the human in these things, but it augments them and helps them work much faster, which is really wonderful for, for our threat modeling work especially. Um, some other examples of things that we've done, um, think about network scanners. Uh, you often need to stay up to date on the latest CVEs, the latest, um, proof of concept code to be able to make those scan templates and to know, you know, which systems on your edge might be vulnerable to the latest vulnerabilities.
Um, so we have found that AI is especially effective if you can point it at, um, you know, public information about these things. Um, it can turn around and create those scan templates rapidly for you, allowing you to more rapidly find those places in your ecosystem and ultimately more rapidly solve the problems of fixing them. We also use it, um, internally for developers.
Uh, we like to give them as much information as we can around the security problems that we find and code and help them to fix them quickly. And, um, we have found that it's much better to provide some context around this is how we think it should be fixed. Um, this is the best practices around fixing it and those things as opposed to just saying, here's the problem.
And in those situations, um, uh, gen AI is actually pretty powerful at being able to, um, put together some of those recommendations so it can actually go into our Jira tickets and augment them, um, so that people can get additional context around the best practices for their fixes and, um, and ultimately get to a, a faster conclusion on them. Excellent. Brian, everyone today is talking about agentic AI and AI agents.
We're, we're definitely looking at, um, different ways that this can play out. Um, we have, uh, been exploring code generation, um, using some agentic AI systems. And one of the interesting things in this space is that, uh, you, you can ask it to help you make code, um, and sometimes it does it in a way that's very secure and sometimes it will miss a few things like, um, like path reversal vulnerabilities or SQL injection.
Maybe it doesn't quite do the right filtering on that input. Um, but what you can do then is you can actually tell those systems, here's some additional guardrails I'd like for you to consider before you generate that code. And then all of a sudden, the code that it generates, it's the bar is raised in terms of the security quality of the output, um, and a world where more and more code is likely to be generated by a AI year over year.
If we can get ahead of that curve, and if we can actually, um, ensure that that code is more securely written than what a human would've done, then we can actually move the needle on security over time. So I'm very excited about, about that space and where that's heading. Um, we're also using it in, um, more of a chat bot situation, right?
So, um, someone can come into our team and ask questions around, Hey, what's the best way to protect my password, right? Or, um, you know, any sort of question they might have. And a lot of these things are actually written up as internal policy here at Adobe.
And so it's pretty straightforward for AI to be familiar with all those policies, look at the question, match it, and then respond for them. And, um, that allows us to get answers back to the workforce much more rapidly than, uh, than having a human in the channel all the time. And we can go back and, of course, double check, do we think it gave the right answer?
And then kind of train it over time in the cases where maybe it missed. Brian, thank you so much for, for, uh, coming on here today for people who maybe just wanna find out a little bit more about Adobe security in general and maybe about how Adobe's using ai, uh, you know, for security, where, where can they get more information? So I would say definitely, uh, you know, enjoy these episodes where we're gonna talk a little bit more in depth about our work.
Um, we also do often speak at conferences, uh, in the, you know, the technical conferences throughout the community. Um, probably too numerous to list, but I would just say keep an eye out for, for Adobe at your favorite security conference. We are quite often there, so Absolutely.
Brian Payne, VP product and software security of Adobe here. Thank you for joining us, Brian, and keep up the great work. Thank you, Alan.
It's been great. I want to introduce you to our next guest in this series. His name is Alex Stan.
Alex is the senior pro product security engineer at Adobe, and he's responsible for triaging and validating bug bounty reports, planning, life hacking events, developing security automation for scale and, uh, to scale the program's activities, and as well as collaborating with the various stakeholders, both internally and externally to improve security workflows. Alex, that's a mouthful, but welcome and it's great to have you here on Textron tv. Thank you, and very glad to be here.
It's obvious. What are the, what are the benefits to a company like let's say, Adobe, um, with having a bug bounty program? Well, you're gonna find out, hopefully your software becomes more secure as a result, because there are people who are not, you know, who are on the outside looking in, let's say, or who are, you know, beyond the team who are letting you know about, uh, potential bugs and defects in your software.
Or maybe they're features, right? It's not a bug, it's a feature, but what's in it, what's in it for the security researcher who discovers this? Yes, for sure.
And, uh, of course that I, I cannot, uh, you know, it, it's just financial. Uh, it's definitely one of the main reasons. Uh, but they do have some advantages.
Like I I think internal flexibility. They get to choose their targets. They can hack whichever company they, they want, like if they're specialized, maybe in desktop testing or web application testing or mobile testing or cloud, large language models, they, they, they can try to test everything they want.
And also there is, uh, an, an important part to this, which is the reputational aspect. Um, they get recognized by the companies. They maybe, um, have CVS on their day name, you know, they report the vulnerabilities in the program, which is a CV number authority issues, the cvs, they can sign a cv.
So, uh, it's, it's a great aspect on the reputational part as well. Absolutely. And, and that in many times, many ways, it's even more, that's more of a, of a, a carrot, more of a, of a reason to do this than, than some of the financial rewards.
But now we, of course, Alex, we're in a new world, right? We've got AI and we've got, well, even before ai, I remember when fuzzing came out, right? All of a sudden that made, you know, doing scanning with a fuz, they, you, you could do a lot more with that than you, than you did with the old way of, of doing it.
But talk to us a little, talk to us a little about how bug bounties are changing in this new AI world we live in. Definitely, I, uh, believe the bug bounty hunters are using AI and large language models to, you know, help, uh, discover more exploitable opportunities. But we, on our end, in the programs we need to scale as well.
So we're trying to definitely leverage ai, um, to reduce our, you know, our manual tasks and focus on the more important tasks. So I can give a little examples if that's okay. Sure, please do.
Cool. So, um, we definitely from time to time, you know, as, as, uh, backbone program owners have a lot of reports, so we do want to ensure, uh, we are doing report validation, very efficient. So, uh, one of the manuals tasks we, we have to do is maybe identify duplicate reports.
It's, uh, mostly unfortunate, but, uh, bug multi hunters are, uh, can find duplicate reports of one another on our end is, is pretty tricky to, to, uh, bid the pieces together. Um, and we try to use olms to maybe identify, uh, duplicate reports and also maybe the LLM can assist on the reproduct reproducible aspects. Like if there are unclear steps to reproduce, like for example, I'm not sure from step three to step four, um, how I can actually reproduce the finding, but maybe the an LLM can already do an, an analysis for us before we actually jump into the report and, and provide the extra steps or, uh, make, uh, you know, some, some distinctions maybe DLM telling you, you can go back to the researcher, ask more information about this or, uh, it isn't enough security impact illustrated.
Can you, can you show us, um, so it actually help us, uh, reproducing. So yeah, uh, this is, uh, usually how, uh, LMS can, can help with a report validation. There are others application as well.
Absolutely. Alex, I want to hit on two things. Number one, you mentioned you as, you know, the a person at Adobe who goes through all of these bug bounty reports that you receive.
Give us an idea how, how big a job is that in, in like sifting through all these reports, eliminating duplicates, finding out which ones are, are in fact valid, which ones are critical, which ones are not deciding how much money a bounty should be paid on a particular thing? I, if you wouldn't mind, you know, 'cause that sounds like a huge job and then it, you know, now in the age of ai, is the aim to replace the external researcher with the internal ai, or is it really you want the, you want both? I think my answer is we want both.
Uh, especially since, you know, the external researchers are very creative. So an AI definitely cannot, uh, cannot get to that level. Um, and regarding the volume and, uh, let's say the technical, uh, technicality of the findings, uh, yeah, it, it's, it is challenging and yeah, we, we need to handle, uh, the payout.
So we need to assess each finding correctly. So, uh, in the order of ai, uh, actually another application is to auto enrich reports. So we have pretty much a lot of findings, right?
So, uh, we can use an LLM, for example, to predict CVSS score based on similar reported findings. So we don't have to each time, uh, need to check those and see we, uh, we align with, you know, with previous submissions. And, you know, of course there will be many bugs and many products reported against.
We can also use the LLM to identify the product that is reported against and pre-populated, uh, in, in a ticket and actually categorize the findings. So in order to track the findings, you, you need to, to know like certain information and what's the vulnerability? Like, is it cross scripting?
Is it SQL injection? What's the proposed CVSS score? Because, because of, on the CVSS score, where you pay the bies was the reported product.
So, um, yeah, uh, the LMS can can be used for that as well. So it sounds Alex, like the, the, the LLM, the ai, right? Because the LLM is just sort of the, the data from which the AI is drawing upon, but we could use the ai AI to, to actually manage the Bug Bounty program itself, right?
So in addition to finding particular bugs using an AI and, and LLM, we could use the AI LLM to manage our Bug bounty program, contact the researchers immediately see, is this particular report a duplicate of one we've already received, as you mentioned, uh, uh, take a, a, a shot at predicting what the CVSS score would be for this book. I mean, it really, it sounds like it makes you job a lot easier. No, Yes, it is.
Uh, but yeah, that comes with, uh, a limitation actually because, uh, uh, it's, uh, providing a lot of extra value, but it needs to be verified. So, uh, we have all the information there, but, uh, in the end, uh, human touches is required for these. So, uh, and we really want to give the, you know, the researchers a chance to, uh, like we want to understand them.
We don't want them to be blocked by, you know, an AI decision. So that, that's definitely a limitation. Absolutely.
Uh, well, it's not just in this particular instance, I think that's good lesson for everyone who's using AI chatbots for customer support and, and service and so forth, is people do get fussed. I, I'm, I'm the first to admit it. I'm the guy yelling representative.
Representative, you know, I want to get a real person to talk to. Uh, and, and I think it's, it's true in bug bounty programs too, Alex, we're almost outta time for, we have a huge security audience here for security folks out there who say, you know what, I'd like to be involved in the Adobe Bug Bounty program. Where, how can they, how can they get involved?
For sure. com/adobe and read the policy, the assets in scope, and start there. com/adobe.
Alex, Hey, keep up the great work. You know, everyone, every, all software has bugs and vulnerability, right? Vulnerabilities.
I, and it can happen to anyone. I, I've learned a long time ago. Don't point fingers, but Adobe's done a great job, I think, and the Bug Bounty program is one of the ways that you guys have done a great job in ensuring your software is the most secure and safest it could be.
So keep up the great work and keep us posted. Thank you very much. D thank you.
We'll be back with more information and insight into Adobe security. I want to introduce you to Omkar ni Bakar, and hopefully I pronounced it right, but, um, this gentleman's too nice to correct me, I'm afraid, but I, I hope it's the right, uh, pronunciation. Omkar is the senior manager cyber threat Research and intelligence at Adobe Omkar.
Welcome to Techstrong tv. It's great to have you on here. Yep.
It's my pleasure to be here. And you pronounced my name absolutely right. So it is, thank you for that.
Thank you. Thank you. I try.
So, um, yeah, I gave them your title. What, what is it, what does it mean when you, uh, you know, when we talk about threat research and intelligence? Sure.
Uh, I can definitely talk a little bit about that. Um, so I lead a team of cyber threat researchers responsible for proactively identifying and analyzing adversaries, tactics, techniques and procedures, gtps, um, and which who are also responsible for providing actionable intelligence to enhance OB security posture and support overall incident response efforts. So that's what the team does, but at the core, it is really about threat intelligence.
And if you look at the whole, uh, idea of threat intelligence, threat intelligence at the core is practice of gathering, analyzing, and disseminating intelligence on current and emerging threats so that you can strengthen your overall defenses. So the trade craft really focuses on gaining deep insight into understanding who your adversaries are, understanding their tactic, tactics and targeting strategies so that you can generate actionable intelligence to proactively different against their attacks. Uh, the goal here is really to get insights into adversaries intense capabilities and opportunities so that you can inform risk-based decisions to enhance defense posture.
And when I say enhance defense posture, there are multiple ways to do this that threat intelligence really helps with. Uh, like, for example, threat intelligence is kind of an input loop into threat hunting exercise. So that based on adversaries threat intelligence team is tracking, threat hunting team can go and look for specific behaviors of that tactic, techniques and procedures into the organization's environment.
Threat intelligence also informs detections engineering, so that detections engineering can actually instrument a lot of detections for the adversaries that would be interested in your organization or would've actually targeted your organization in the past. So the overall goal of threat intelligence is to make it more actionable and timely in order to, um, improve overall defense posture in multiple ways. Makes sense, makes sense.
Um, now, like, like almost everything else, AI has the potential to change the game here, right? And not only to future tense, but is in many cases, is today. Talk to us about how, how AI is, is changing how Adobe does threat in research and intel.
Yep, absolutely. Uh, and you're absolutely right, like AI is changing like our lives every day. Uh, and from work perspective, like as we think about technology, so when I think about ai, like it is so much evolving, and similarly when I think about like overall threat landscape, uh, for industry that is also always ever evolving.
So these two things, uh, connecting together are really helping solve like a lot of problem space in threat intelligence world. So by leveraging ai, uh, threat teams can really automate and augment like threat analysis performed by a human threat. Intelligence teams can move from reactive threat signals triage to more strategic proactive defense.
And I, I can give like couple of examples in the way we are doing this here at Adobe. So what we call it as AI powered threat analysis. So large language models, LLMs are able to digest and understand vast volume of unstructured data from various threat intelligence reports, block articles, research peoples that are talking about specific attack campaigns.
They have specific context around adversaries, what their tactic techniques and procedures look like, what their indicators of compromise are. So LLMs can easily digest this information, identify patterns in a much, much better way with more contextual insight to extract indicators of compromise so that organizations can actually go and, um, look for those indicators across your environment. And what this really helps with is automating threat analysis for emerging threats by reducing manual bandwidth.
Like if you look at the news, like there are so many threats every day that are evolving, like the landscape has been rapidly changing. So for humans to, for the analyst or researchers to actually sit down and analyze that every threat, it's a very manual type bandwidth consuming tasks. So AI is really helping us to do that faster and better by reducing noise overall from threat feeds, prioritizing relevant indicators of compromise based on organizations context, which ultimately helps with faster dissemination of intel, uh, where the goal of intelligence is really to make it pioneer and also actionable.
So that is one example. Uh, the other example that I can give is threat landscape report generation. So I'm sure like, like Adobe, every organization would be interested in understanding what their threat landscape looks like.
This is where AI can really help by analyzing both external threat data, uh, through multiple sources, both public, there might be some vendors providing threat intelligence data. So AI can actually help analyze external data as well as internal organizations signals to generate more tailored threat landscape reports for executives, for security teams, uh, for various engineering teams, which can be, uh, created at regular cadence. Uh, so that all those teams are informed about evolving threats specific to their organizations or specific for their team.
Um, so the benefit here is really, uh, rapid and relevant threat landscape reporting with minimal manual effort. And the best part about this is that ai, due to the contextual understanding, um, AI is able to generate tailored threat intelligence for specific organizational needs so that it is more tailored for your use case and not generalized. I love it.
So mka, I'm gonna ask you a important question important to our audience too. We're all hearing how AI might replace people. You know, they're, we're calling some of these agent AI things, digital workers, right?
As you sit here and, and how Adobe is using it. Is it, is it replacing anyone on the cyber threat intelligence research and intelligence team? Or is it augmenting and, and making you more effective?
That's a really good question. So I don't believe like AI will is replacing threat intelligence analyst as of today. As I think about AI, technology definitely helps augment human analysis and it helps us be better and faster at what we do as threat researchers compared to like replacing.
So it's a little bit away from replacing and, and the reason I see this is because, um, AI is better, but it is still not at the point where it would really replace, uh, like we still keep seeing false positive based on what AI generates because it really depends on what the quality of data that you are training your model on. Um, it also has like a lot of contextual awareness, but it still requires human oversight for decision making in some cases because AI might miss the nuances that a seasoned security professional would catch it immediately. So it is definitely a game changer to augment and make us faster at what we do, but I don't believe it is at a point where it'll replace us right now.
But it definitely augments and makes you more effective, and I think that's the important thing. Yep, absolutely. It is definitely a game changer in that way.
Excellent. Omkar, thank you for coming on and talking to us about threat research and intelligence, which, you know, was such an important arrow in the quiver for our cyber teams today and about how you're using ai. Again, another really great example of how AI is making us more effective in our cyber jobs and making our security better.
Thank you. Awesome. Thank you for having me, uh, it was a pleasure talking with you.
I'm happy to introduce you to our next guest. His name is Poin eSSH. I hope I've got that right, but if not, please correct me.
P Poin is a, a senior application security engineer. Poin, welcome to Techstrong tv. It's great to have you on.
Hi, Alan. Uh, great to be here as Wellen as a senior application security engineer at Adobe. Talk to us about how you are harnessing the power of ai, and not just you, but Adobe and your team and teammates.
How are you guys harnessing the power of AI to define the future of security? Right. Yeah.
Oh, great question. So, uh, I'm essentially part of like the threat modeling team. So we handle like the threat modeling efforts across, uh, the board for Adobe.
So, uh, one of the ways that we are exploring to leverage AI in the threat modeling space is to make sure that we can, um, essentially have like better, faster feedback to product teams. Because as a small team, scalability is one of the, our primary issues, right? So, uh, the way we're thinking about this is making sure that we can leverage AI at the early stages of like the SELC process where teams can come and provide us a little bit of information, and in return we provide them with potential threats and potential mitigation strategies that they can leverage.
And from there, if we see any critical issues or areas that we want to manually focus on, that's where we would like go ahead and do a manual threat model or like the traditional threat model, if, I mean, so that's how we're currently thinking about leveraging AI in the, in the threat modeling space. You know, you, you think about it, it would seem like threat modeling is probably a, uh, a great area to harness the power, the positives that AI brings to it, that AI brings to a, you know, an issue like that. Can you dive in maybe a little deeper about why AI is a, is a great technology for threat modeling specifically?
Oh, yeah, for sure. So, um, over the last year or so, we've started leveraging like, uh, an LLM to essentially analyze like architecture diagrams, the use of flow diagrams, as well as like any documentation that the team provides us. And based off the documentation itself, we, uh, would be able to like look into, uh, and understand the context, the LM would be able to understand the context and then provide back potential threats and mitigations.
And right now we're exploring the concept of using agentic pipelines. So, uh, one is essentially figuring out, uh, one agent will be figuring out what the content looks like, and if there is not enough content that the, that the pro product team is provided, then getting back to them saying, Hey, can you give us more details about your authentication, your authorization, maybe how you see, uh, how you store your secrets, and so on and so forth. And then from there, we have another threat detection engine.
So this is where like the meat of it happens, right? So, um, this essentially takes all the context that, um, the product team has provided along with like a prompt that we've created that would then like provide us with a list of like the top end number of threats that might affect the product itself. And that is where we go into the interesting phase.
So we are currently leveraging what we call like a, a retrieval augmented generation system or a rag system for us to like provide the mitigation strategies. Before what we were doing was more so just leveraging the base or the foundational knowledge of the LLM to provide mitigation strategies. And that wasn't working as well because like, um, it would just be a little generic in terms of like the medications, uh, in, in terms of what it, uh, gave us back in terms of the mitigations.
But, um, right now the way we're doing it is, uh, hey, these are the documents that we have curated over the last few years that are very Adobe specific, that, uh, talk about like the products that we use at Adobe, the solutions that we use at Adobe, and then that is leveraged by the LLM to provide very specific or pointed, uh, mitigation strategies to the team. And we're hoping that this would make it more actionable for product teams to leverage and, uh, at the same time make sure that they don't see, or like, it doesn't make it too generic to a point where they don't leverage the medication strategies altogether. So that's essentially the parts that we're moving towards right now.
Love it. I love it. You know, I, I'm just realizing and listening to you talk.
I I've been in security a long time. I, I of course understand everything you're saying about what you do in threat modeling, but you know, Adobe does threat, not just Adobe, but a modern cybersecurity strategy to includes threat intelligence, threat modeling. If you wouldn't mind take just a quick minute talk about how these, these things, you know, how they go together, but yet they're each their own sort of independent, uh, discipline, if you will.
Oh, yeah, for sure. So, uh, threat modeling is sort of moed over the last few years, but essentially it is a very systematic way of like detecting potential issues and like providing mitigation strategies for teams very early on in the development life cycle. So you can think of it as like a shift left strategy.
And, uh, the way we would approach it is essentially understanding like, uh, the components that are being part of like a particular workflow, the way they interact with each other, uh, how data flows from like the entry point all the way to the exit point. And, uh, if there are trust boundaries, how those trust trust boundaries interact with each other as well. So, uh, essentially understanding the complete picture of how a product works and then figuring out where there are weak points or like potential areas where new risk or, uh, potential threats can be introduced.
And once we identify those, we share that with the product team along with like a curated list of, Hey, if you do this, this potential risk can be mitigated, and so on and so forth. So, uh, this, uh, threat modeling essentially becomes like a part of the early, uh, se early part of the development lifecycle, but we essentially try to like keep that flowing from like the ideation phase all the way to production so that we help teams like secure their workflow, uh, from from to shift left to right. And the earlier we do threat modeling, the better it is purely because it reduces the kind of double work that teams need to do to like prevent these risks from happening after they go to production itself.
So, uh, that's where, uh, threat modeling as a concept comes into play, and that's why it's so important in the industry right now. Love it. This next question is the most important question you're going to get asked here.
So give me a good answer on, we hear so much about AI taking people's jobs. We hear also about AI helping people with their jobs. When it comes to using threat to using AI and threat modeling, maybe even with ag agentic ai, is it replacing security engineers or is it making you more effective in your job?
Oh, great question. And the answer is resoundingly, uh, to say that it is making us a lot more efficient. I don't think, uh, agentic pipelines or however complex these AI systems become, it would, uh, replace our jobs altogether purely because there is that human factor that comes into threat modeling.
We understand like the, the nuances between how companies interact with each other, uh, the, uh, the business impact of like a potential threat that could, uh, affect a particular product. And there are other human aspects that cannot be like taught to an ai. But at the same time, having said that, it does make our lives a lot more efficient with the introduction of AI itself because, um, we call it the low hanging fruits, but essentially, uh, AI is able to cover our basis when it comes to like, uh, the lower risk areas or like, uh, some of the gotchas that are easy to detect.
And that is where it helps us, like cover our bases. And from there, if there are any critical components, we go in and still continue to do like a manual threat model. So, um, essentially think of it this way, right?
Instead of doing like, um, 20 threat models, we are able to focus on the top five highest risk threat models, and the rest of it is sort of handled by ai. So we are able to focus our time and energy towards the, towards the critical workflows that matter for Adobe. And that had like, uh, like dire consequences if there is like an issue with that workflow.
So I would say that it is not replacing our job, but like making our lives a lot better and our work a lot more efficient. Got it. I think a lot of, a lot lot of, uh, security engineers are breathing, breathing a sigh of relief.
Ha ha. Hearing you say that. Um, one last question.
This, this AI stuff is evolving so quickly, it, it seems like every day it's like a generation ahead. How is Adobe and yourself, how are you, how are you staying ahead here? How are you continuing to kind of ride the crest of that wave?
Oh, uh, great question again. So, uh, what we do at, within our team is spend a lot of time doing open-ended research on like topics, essentially making sure that we do a lot of research in the areas and trying to keep up with the trends. Just yeah, open-ended research, making sure that teams reach out to us, uh, early on in the development life cycle so that we can like, learn with them as they're like experimenting with the new LMS or the new workflows so that they're doing it in a secure manner.
So, yeah. I love it. Wan I wish we had more time to talk 'cause this is such an interesting area, but thank you for coming here on techstrong TV and, and talking to us about threat modeling and AI and how Adobe is harnessing AI to stay ahead here and, uh, keep us all more secure.
Thank you. Have a great day. Our next guest in this series is Shrudy Gupta.
Shrudy is the product security, AI and data engineer at Adobe Shrudy. Welcome to Techstrong tv. It's great to have you on here.
Thank you So much. A it's great to be here as well. So let's, before we dive into topic at hand, let's talk a little bit about yourself.
Give us an idea of your journey and how you came to have this role at Adobe. Yeah. Um, yes.
So I am a product security AI and data engineer. Uh, I've been at Adobe for four years now. Started as an application security engineer, and then my role evolved into what it is right now.
So basically my background is at the intersection of cybersecurity and, uh, machine learning and ai. So I've always been curious about how do we apply AI to solve cybersecurity challenges. And, uh, that's at the heart of what I do right now at Adobe.
So I, uh, research and develop AI capabilities that can enhance product security. And, um, in addition to my engineering role, I'm also the product lead for my team. And in that function, like in that capability, um, I am responsible for understanding developer needs, translating that into what we are building, um, communicating and collaborating with stakeholders, and also setting the long-term vision for what we are building.
That's a great role. What an interesting role because in some ways shady, you are the conduit, the translator, if you will, of what business is asking for, what the developers, the non-security folks are asking for, and dealing with the security team as well. And then fashioning what really is new technology when it comes to AI and agentic AI to kinda meet, meet those needs.
What a, what an interesting intersection to be at at this moment in time. Absolutely. Let's talk a little bit about kind of things you're doing.
And I, when, I mean you, I don't mean just you personally, I mean your team, things, you, you guys are building, deploying, using, along these lines that are helping to define how, how AI is being utilized in security by Adobe. Yeah, absolutely. So we, my team are basically building a suite of AI capabilities that are designed to reduce product security toil.
Um, and the way we want to achieve this is by making security guidance, security knowledge, security expertise more available, more accessible to product teams whenever and wherever they need it. Um, and those services that we are building, we are, uh, we are making them available as, um, API endpoints. Basically they should, anybody at Adobe should be able to use them in a self-serve manner, and you can integrate our services seamlessly into existing developer workflows.
So think, uh, messaging platforms, ticketing platform IDs, web widgets, et cetera, right? So be where developers are, uh, provide security guidance as in when they need it. And for this, we are using ai.
Um, so fundamentally we think of all the stuff that we are building, uh, we kind of categorize it into two large buckets, I would say. The first is, um, AI security assistance. Um, you can also call it ask security.
So anybody at Adobe can come to the assistant, ask their security question and get an answer. And now we are doing this by leveraging Adobe's internal policies, uh, standards developer product and platform documentations so that, you know, when a developer is coming with a question, the AI assistant can answer that question in a way that is as close as possible to how a human security expert at Adobe would answer that question. So that's one.
And then the second pillar is, uh, remediation recommendations. So, uh, we want to equip engineering teams with the right resources that they need to remediate to fix vulnerabilities. And again, for that we are using Adobe specific information, Adobe specific product specific best practice guidance, trying to understand the context in which the vulnerability is, and then put all of that together to provide the guidance that can aid the developers, that can enable them to go fix the vulnerability.
So these are kind of like the broad two categories, uh, of capabilities that we are building. So in, in hearing you describe them, they sound to me more almost chatbot type of things where an engineer could say, Hey, how do I, what's this vulnerability? What's the best way to patch it or remediate it?
I know patch is a mm-hmm, mm-hmm. An old word. And, you know, these are great chatbot type of, uh, opportunity or description.
So, uh, Go ahead. Yeah, no, no, go ahead. I think you know where I'm going.
Go ahead. So, uh, chatbot is one way to get this guidance wherein yes, like you have a, you have a chat bot, the developer comes to the chatbot, asks a question and gets the guidance for their question, uh, be it generic guidance, or how do I do X, y, z, or how do I fix a bug, right? Um, one of the other ways that we are doing this also is when we find, uh, security bugs, uh, we have a process for ticketing them.
You've spoken, uh, with, uh, like Alex on the bug bounty side. So we, we create tickets and then we assign those tickets to the developers. So another way that we are integrating in that existing workflow is, um, call our APIs that understand what the bug is, and then provides remediation guidance in the ticket itself.
So when the developer is assigned the security ticket, they don't just have, uh, a description of what the vulnerability is, but they also get a guidance as to how they can go about fixing the vulnerability. So, so that is how we are doing it today. We also, of course, have the chatbot functionality.
Another aspect is, like right now, um, AI assisted IDs is the new thing, right? Like it's gaining a lot of popularity among developers. So that's, that's another outlet.
So as developers are writing code, how do we detect vulnerabilities? And instead of having the AI agent in the IDE provide like a generic guidance, how do we get that tailored to, uh, what Adobe recommends is the way to go about it? So that's another way to kind of, um, address this and make this information available to developers.
Let me ask you a big question. Sure. When do you think we'll see agents that actually go out and just do this and kinda tell the human after the fact, if you will, or do a report, but they're actually doing the remediation in an autonomous type of, uh, setting like that?
Yeah, that is a tough question, right? And I think, uh, it's, it's an ambitious goal as well, right? Of course, that would make all of our lives so much easier.
But it's also difficult goal to achieve with state of the art AI models and AI agents. The thing is, when you're talking about a single code file or like a small enough code repository, state-of-the-art models do okay-ish, they, they can be hits and misses. But the thing is, like at Adobe, each product team is so different.
Our code bases are vast. So realistically, I would say we are not there yet, uh, wherein we can have AI agents figure out what the fix is and go do it, uh, at the PR level themselves. And I would say we don't necessarily want that.
Also, um, in my team, since we've been developing these AI capabilities for what, almost one and a half to two years now, like, we have learned along the way that human feedback, human in the loop is absolutely critical in these workflows. Um, like we don't think that the answer is to give the AI agents a hundred percent agency, uh, but there has to be a human oversight involved, right? Like these agents are, uh, very useful when it comes to doing the manual laborious, tedious tasks, right?
Like going through documentations, um, like finding the right resources, those kinds of things. But at the end of the day, uh, we do need, like, like our recommendation also is that there has to be human oversight involved. Go take a look at what the AI agent has produced, what the AI agent has generated, right?
Does it meet, meet your requirements? Does it meet the, the, your requirements, what you've asked for, what, what the right way to do things is, and then you kind of, for the lack of a better term, approve those changes. So I would say that's, that is more realistic than, uh, like let agents go to whatever they want to.
Uh, I don't think, um, even with the state of the art, we are not there yet. Yeah. Trudi, I wanna thank you for coming on and talking with us today.
As I said, the time goes quick. Keep up the great work though. And then this is, as I said, an exciting place to be in this moment in time.
So good luck to you absolutely. Shati Dr. Gupta, product security, AI and data engineer at Adobe.
I hope you've enjoyed this session of four or five actually segments of different areas of the Adobe security team using ai, leveraging AI to make their software more secure and make your work more secure. I hope you can take these lessons and apply them in your own organization as well. Thank you.
Alright, Sachin, I'll, uh, count it from five. I'll do a Hollywood count and then I'll get going. Okay, sounds good.
So, 5, 4, 3. Hi everyone, and welcome to the six five Summit AI unleashed for this cloud infrastructure spotlight. I'm joined by Sachin Gupta, vice president and general manager of Google Cloud's Infrastructure and Solutions Group.
We're gonna be talking about infrastructure innovations to, uh, to accelerate AI solutions. Sachin, thanks for being back. Good to see you again.
Yeah, great to see you again too. So, let's talk a little bit about cloud Before we dive straight into ai. Tell me a little bit about what you're kind of seeing as some of the most significant trends impacting cloud computing in the current market.
Well, I think, you know, you'll get the same answer from everyone. It's all about ai, uh, generative ai. I mean, it's moving so quickly and we've talked about hundreds and hundreds of unique applications and how customers already, you know, moving to agents and solving problems in, in many unique, innovative new ways, leveraging the power of Google technology, the Google AI stack.
And so innovation at every single layer of that AI stack, you know, from infrastructure, AI platform, all the way up to models and agent development capabilities is super important. That's what we hear about repeatedly from customers, help them out on that. But then with ai, I mean, to get the best out of ai, you need to manage your data.
And so how do you get your data, uh, into your models and then your users connected to those models, connecting all of this, these environments, bringing your data to the right places, doing it securely, efficiently, low latency, all super important. And then finally, all this stuff can get be super expensive. So how do you manage cost?
How do you make sure you're getting the, you know, most bang for your buck? Uh, there's, you know, one plus one equals more than two because of architectural advantages, et cetera. And how do you just save on cost?
Like if they, there's data you're not accessing frequently, move it to colder storage automatically. So leverage almost AI operational capabilities to reduce cost as well. So, uh, it's all about ai.
It's all about how do I get my data to the right places and think about networking especially, and then how do I think about cost? Yeah, I'm, I'm glad you, you didn't fall for my trick question. I came out the gate and said, we're not gonna talk about ai, but this event is AI unleashed.
But I think the thing that you sort of really answered very nicely there is that the cloud and AI have become synonymous and symbiotic in many ways. And the other thing that's, that I think is going on that's really, you know, you called it everything ai, but it's also really about a very new stack. And the cloud is powering that.
Like if you kind of think about what it looked like before this, there was like this CPU era cloud and everything over the last few years, and by the way, this has been wonderful for Google, but as the cloud was sort of reborn, um, you know, I call the CPU era and the GPU U era. Now that's not exactly right 'cause there's also the TPU era, but you know, we've had these kind of multiple eras, and now the way you build applications is different, what you've built with Vertex and sort of democratizing, now you've got new languages that allow us to build agents that can talk to each other. And all these things are really made possible by the three things that you mentioned.
Having a sort of AI first approach, building your cloud to be hybrid, multi depending on your, your enterprise's architecture. And then of course, I like that you did, you know, most cloud providers would never acknowledge that cloud, uh, cost is an issue because, you know, as far as you're concerned, run the meter, right? I mean, I joke, right?
I digress. But like the, the joke is, you know, obviously more use is good, assuming it's productive, right? Assuming it's productive.
Yeah. You have to get efficient use out of that infrastructure. Yes.
Yeah, no, I mean, look, if we're using, if we're spending to make, that's a great thing for business. It's the problem, like you said though, is sometimes it gets very expensive very quickly for, you know, development effort. Sometimes it gets very expensive just to run the business.
And this is where cloud management has to be, you know, cost management has to be thought a lot about. Another thing that I think has to be thought a lot about session is security. Mm-hmm.
Um, you know, part of bringing all your data to the cloud, trying to deliver ai, and by the way, trying to do it as fast as companies like yours are doing IT, enterprises in every industry trying to take advantage of cloud to run simple, monotonous day-to-day things, and use AI also to build and expand and innovate their companies using ai, is there's pace with that. PACE comes exposing data, it becomes exposing workflow systems creates a lot of risk from, you know, especially from the network as you're just trying to move all that data around. Talk about how you're thinking about security from that networking context.
Yeah. Let's talk about, uh, network just from a sheer connectivity aspect first, and we can touch on security after that. Um, because you raised some really important points.
If you've got your on-prem data center, you've got, you know, you're trying to use G-P-U-T-P-U resources in one or different cloud providers. Connecting this environment at high performance, low latency cost effectively is just increasingly complex. I think Google has taken a leadership in hybrid and a multi-cloud where, for example, obviously you can interconnect into Google Cloud, but we also enabled cross cloud interconnect so that we will deliver the SLA for you, make it much easier for you to connect multiple other cloud providers directly into your Google Cloud environment so that you can move data across more cost-effectively, make it easier for you to run operations in this environment.
We've that now, uh, added, uh, a few more capabilities. If you want to take your SD-WAN head end and run that in Google Cloud, you can do that. And what that means is the traffic stays on our backbone for as long as possible, giving you a much better experience.
We're adding a new capability called cross site interconnect. You can take two of your own sites, maybe two of your own data centers and connect them through Google Cloud. There's a new capability that we launched called Cloud wan.
Now, in reality, because your data can be in different locations and you need to bring it all together for training for ML inferencing, you need to start thinking about that WAN that you had historically, the wide area network as a new land from a performance cost effectiveness and a latest point of view, we're now providing the Google backbone, the Google wide area network, if you will, to enterprise customers as their own with land like performance. And so 40% better performance is what our customers are seeing with up to 40% lower total cost of ownership. So completely changing how you think about connectivity, high performance, and how you manage those costs in the world of ai.
So let me just pause here, um, before we talk a little bit maybe about security as well. So hopefully that makes sense on how we're making our backbone the only backbone that enterprises need to worry about at for any of their connectivity needs. Well, I I think you hit an important point.
Enterprises need to sort of think about where to orchestrate different layers of this new stack. And I think if I'm hearing you, you know, you're really talking about Google is really trying to address that orchestration, you know, to simplify network. Same thing you're trying to do with, you know, agents and other parts of the AI stack is, it's never gonna be all in one.
I think Google's acknowledged that from kind of day one. It's ne, you know, ideally most enterprises are gonna have some on-prem, some edge, some cloud, maybe more than one cloud. They've got a network, all these things.
And then of course, they have to be able to run these things and, but you're not gonna want orchestration at every at with every one of these things. So it sounds like you're trying to address that now, carry me over to the security side of, of this. Yeah.
How does this impact security? So, you know, like, look, so we obviously moved compute to cloud storage to the cloud. We're saying your entire network is actually delivered to the cloud.
But if we did that and said, Hey, now the only security stack you can deploy is the one we offer, and your best of breed that you stack that your security teams might, might have certified on, you can't deploy anymore. Well, that creates friction. You now have to change things around.
I mean, I don't want to change my security stack to necessarily as an enterprise customer. And so we offer two things in conjunction with Cloud wan. One is we offer the best of breed security capabilities ourselves.
So our, for example, our anti DDoS product with Cloud Armor, we've stopped the largest attacks in the world with that product. It's just built in into Cloud wan. Second one I'll point out is our cloud next generation firewall.
It has up to 20 times the efficacy of competitive solutions. Now, those are our products. If you are using SS e services from Palo Alto, checkpoint, or Fortinet, and you wanna use our backbone, but you want to use those security services, we natively integrate those services into our backbone.
And so with Google, you can bring your third party services of choice and seamlessly get them delivered virtually through our cloud instead of being forced to say, no, no, no, the only things you can use are the first party services we provide. Now, of course, as I said, our first party services are also industry leading. Yeah.
And choice is kind of another theme here, right? Sachin? Yeah.
Let's talk a little bit about a efficiency, you know? Mm-hmm. There's kind of the, we've all, we've kind of hit on all the rate limiters, you know, but in, in the era, you, you really have your compute network and, and power are the three things that are sort of, but in the end, like you wanna do, you need enough compute, enough, uh, network excess and enough power, but then you want to get as efficient as possible.
You wanna put the right workload on the right silicon, um, you know, to try to optimize this is cost impact, this is energy impact, all these things. So when it comes to optimizing for AI workloads, you know, you have TPU, you have GPU, um, talk, and you, and you have silicon diversity, you have different GPUs you have, and then of course you have TPU. How is Google sort of thinking about doing this to maximize utilization but optimize for the user?
Yeah, that's a, that's a great point. You know, with these expensive GPUs and tus, if, uh, they're sitting idle, uh, that's a huge problem. And so making sure that you're not just load balancing in the traditional ways.
You know, you're sort of sending flows for web traffic that we typically understand, for example. Instead, you're actually understanding parameters and metrics that come from those GPUs and TPUs, for example, the queue depth, the KV cache, uh, the number of tokens that are being processed, for example, because you may find it that there's a new query that comes in that requires lower latency. Hey, what's the best GPU that can service that at this time?
How, how do you make sure that you're not gonna put that into something with a very, very large queue? And so making sure that you understand what are your different types of ML queries or Gen I apps, what are their needs? And then also understanding how is the infrastructure actually performing with a rich set of metrics.
Like Q Depth, like KV cache, that's something we pull together. And something we call GKE, inference gateway, GK inference, gateway takes all of that, lets you set up the policy and then therefore get much, much better efficient utilization of the infrastructure, which saves cost. Okay.
Uh, so up to 30% savings and cost, for example, but at the same time gets you much, much better performance in terms of lower latency, faster response times. And so we have customers like Snap, for example, already using our inference gateway to improve the performance and to improve the utilization of the infrastructure. So I have to pivot this Sachin because there was a lot there, but I wanna pivot this to, to data and storage.
Mm-hmm. AI is, you know, first of all, it's unleashing applications that are, are, are touching so much more data on a, on an average use, right? Of course, you still have your file and your block and you know, your typical storage.
Uh, but that's kind of the, the, that's kind of the past. We still need it. It's not gonna go away.
But in the future, it's gonna kind of be all about compute, being able to get to all the data, very low latency, structured unstructured, it's gonna be able to discern, utilize access, you know, talk about the kind of forgotten piece of storage to the AI puzzle and, and, you know, what is going to be, you know, critical for being successful in the AI era as it relates to storage. How do you see it over at Google? Yeah, I, I'm, I'm actually really glad you brought this up because I think the amount of innovation happening here is tremendous.
So to support these specific use cases, so you said it really, really well, actually, those compute resources, uh, can operate faster and faster and faster. Like, I mean, every six months, every year there's a new TPU version, for example, it just goes faster. Yeah.
And it can ReadWrite data really fast, but if your storage becomes your bottleneck, again, that expensive G-P-U-T-P infrastructure is sitting idle, your training jobs take longer, your inferencing is slower, it's just not, it's not a great experience. It's not cost effective. So there's two things that we do, again, once again, staying true to choice and making sure that there's open choices that are available to our customers.
One is, if they're used to using a parallel file system like luster on-prem, how do we make sure that we provide the same experience in Google Cloud? We're bringing out a managed luster service, great performance, great scale cost effective for AI use cases, also for high performance computing types of use cases. So that's a open sort of, you know, general compatible, semantically compatible solution.
Many of our customers, though, love Google Cloud Storage, which is our optic storage, has massive scale, very, very cost effective, very easy to use. Well, with Google Cloud storage, uh, there's two enhancements that they've been asking for. We've been working with, uh, customers on to innovate.
One is, how do, when I'm trying to read data, can you automatically cache the data that many of my GPUs at TPUs need to read locally? So that, you know, and we're able to, by the way, automatically do that caching one petabyte, so a large amount of cash, uh, reduce the latency, 70% or so, so that I don't have to keep waiting. I can read very, very quickly because it's cashed locally.
There's something we call anywhere cache. Then we have another, uh, uh, product as part of Google Cloud storage called rapid storage. And Rapid Storage says, I'm actually gonna take the storage you have and put it in a zonal bucket that is right next to your compute, right?
So your GPUs and TPUs, and now you can get sub millisecond reads, writes, and a pens, all kinds of great things. So providing both open choices like Managed Luster as well as innovation in Google Cloud storage specifically for ai, that has just tremendous benefits. 5 terabytes of throughput, for example, using all our, our automated caching solution, um, anywhere cache with the, their ai, uh, models.
I mean, that itself is a, of course, I'm guessing Google's probably using it for some of its own models, but not just your own, it's one thing to be customer zero. It's another when a company of, of doing what they're doing with the types of model size parameters that are seeing what you're doing as the right partner to access the data storage to make their experiences good. Because, I mean, in the end, like you start using these tools and it's slow.
I mean, these are gonna be the small differentiations between one and another that makes us decide whether we're gonna pay open AI $20 a month or, and drop it $20 a month, or Google 20 is gonna be, you know, of course we want it to be accurate. We want it to be, you know, not hallucinate. We want it to have really good insights, but we also want it to be fast.
I mean, that's, yes, that's a big part of what people are looking for. I wanna end this conversation actually talking a little bit about the complex political landscape and, and, and sovereignty. We've heard from a number of companies that that's going to be a big opportunity.
Um, you know, we know that, you know, data, uh, staying, you know, the eu, for instance, has been kind of very well known, very complex data rules, um, in this climate. Sort of, what are you hearing from your customers as it relates to, you know, ai, sovereign AI, data sovereignty, and how is Google addressing this to make sure that you you meet this opportunity? Yes, and I think it goes back to choice and having the right set of controls.
And so what I mean by choice is having a complete portfolio of sovereignty solutions so that customers, based on their environment, their regulatory needs, their compliance needs, can pick the right solution. Uh, and the solution typically involve different types of controls. First set of controls are around data.
So we have something called Google Cloud Data Boundary, which it ensures that you can keep data in your region of choice and you control your encryption keys. You also control who has access to that data. Uh, it's amazing.
It's available across our regions because we see that need in, in many, many, many different countries. We also have specialized offers where you can have operational controls, uh, and we have a, for the most stringent, if you will, like, if you are a defense intelligence public sector, uh, where a type of type of, uh, agency and you simply cannot have your cloud environment connected to anything else, you need something fully air gapped. We even offer that, that with Google distributed cloud.
And so ensuring we've got the full portfolio solutions is super important for us. And as we work with customers, we help them try to understand, look what exactly, where exactly do you fit on the spectrum? Where do you land?
And we have the right sovereign solution for you. One other point I'll just quickly make on that, I'm sorry. I just remember, you know, some of these customers, like, they don't want to trade off innovation for sovereignty, right?
So it's not about, oh, I get sovereignty, but now you can't do ai. And so it's also been super important for us to make sure that with those controls, you still get access to things like Vertex, you get access to Gemini, you get access to things like agent space search. And so we support those on both Google distributed cloud, which is, you know, can be all the way fully air gapped as well as our public cloud regions.
And so it's not about a, a compromise between AI or innovation and sovereignty. You should be able to do both as a customer. And that's exactly what we enable.
Yeah. And, and, and for analysts like us to kind of give the seal of approval, it's gonna be important that the experience is deprecated as little as possible in terms of achieving sovereignty, but gaining access to all the tools that makes AI powerful. And I absolutely believe that is what's going to happen.
And I do believe sovereign AI as a large growth opportunity for the industry, and it looks like from what you're saying, uh, Google is, uh, is ready to meet that opportunity. Sachi, I wanna thank you so much for joining us for this cloud infrastructure spotlight at the six five Summit. Thank you so much.
It was a great chat. It was great to talk to you. Alright, everybody, let's stay connected.
com/summit. More insights coming up next. Hi everyone, and welcome to the six five Summit AI unleashed for this cloud infrastructure spotlight.
I'm joined by Sachin Gupta, vice president and general manager of Google Cloud's Infrastructure Solutions group, and we're gonna be talking about infrastructure innovations to accelerate AI solutions, The six five summit. It's back. And unsurprisingly, we're focused on ai.
And listen, we love infrastructure, we love chips, we love the build out, we love agents. This theme of this show this year is all about getting value out of that. And, you know, we're talking about something that is special in my heart and that is essentially what, what we call it, more insights and strategy, uh, the hybrid cloud.
Um, innovation can happen anywhere, right? It can happen in the public cloud, it can happen in the private cloud. It can happen on the industrial edge.
Uh, and we are going to talk about how we light up these, uh, capabilities. And it is a pleasure mine to introduce Rohan, who essentially runs product for Google distributed cloud. Welcome to the show, Rohan.
Thank you for having me here, Patrick. Yeah, and you know, it, it, uh, I made the bet probably 10 years ago as a company. I was a big believer in the public cloud and, and all the benefits from it.
But I was like, you know, this, uh, it would be interesting, uh, really interesting to have, um, a, a cloud model that was on premises and you have delivered it. Thank you. Thank you very much.
But let's drive in. Let, let's kind of drive, go high level here. What are some of the, um, the macro trends, um, more importantly, the business imperatives that, that are accelerating, uh, the adoption, uh, of AI and in particular, uh, AI on premises?
Absolutely. So we know that gen AI is having an impact everywhere. Whether it is use cases like coding, customer care, improving employee productivity, ai and generative AI in particular is changing every business operation and approach that, that we have seen.
But for a lot of organizations, especially those dealing with sensitive data, with regulations and compliance, or even organizations that require extremely low latency, this geni revolution is kind of a little bit of, you know, feels a little distant because they can't really leverage public cloud for the reasons that we just talked about. And they have the same use cases that we just, uh, mentioned for everybody else. And we want them to be able to leverage the power of gen ai, but do it in their own data centers, in their own premises on-prem.
Yeah. And what I, what I really appreciate is you're giving customers choice. You wanna run it in the big cloud, you wanna run it in the private cloud.
Uh, it, it, it's your choice. And I also saw some disconnected versions, uh, as well that are, that are, that are very, uh, very interesting. So, um, let's talk, uh, I get in front of a lot of C CIOs, CTOs and CXOs, and you know, I always cataloging the, Hey, what are the impediments to scaling, uh, uh, ai?
And I'm curious from your point of view, what are you seeing? What are the complexities? What are some of the challenges that, that they're, uh, sharing with you?
Yeah, and I'm gonna speak now specifically on challenges for on-prem ai. Okay. Start off with the fact that deploying on-premise AI is expensive, time consuming and complex.
And and why is that? It's primarily because a, you're likely dealing with data sovereignty and regulatory compliance, stringent rules based on the country that you're in can absolutely stifle AI adoption and really impact the customer experience. Then you have the complexity of AI infrastructure, as you said, this is a hybrid world and customers have to figure out by themselves, which AI apps can they deploy on-prem, what technologies can be used in cloud, what can be done in a hybrid way?
Yeah, it's extremely complicated and it's not obvious what works where. And lastly, let's also acknowledge kind of some of the cloud exclusive frontier models. Most, you know, gen AI vendors out there have made their models available and accessible only through the public cloud making kind of on premises deployment, a huge challenge.
Right? And Google took a different approach. Google Cloud took a different approach.
We announced the availability of basically the best of Google Cloud AI on-prem in April at our Google Next conference. 5 that will be made available and delivered on-prem using our Google distributed cloud portfolio. Yeah, I was there, I was in the seat.
I wrote, you know, know, I, I have a full team of analysts, but that was, that was a note. That was a note that I took. And then I went to Dell Tech world and I saw it again.
Yeah, it was super, I was super, super exciting. So, um, where are you seeing, uh, the highest levels of interest? You know, we talked about, I think you had mentioned, uh, you know, security, uh, latency, or maybe there's just control that, that, that, that people want or, or there are certain, uh, regulations.
Uh, where are you seeing the, the pockets of interest the most? Yeah, and before I talk about it, I do want to give a call out to some of the partnerships that you, that you just mentioned. So Google is working with Nvidia.
In fact, Jensen was the one who did the announcement on this at Google next. And we are thankful about that. Adell is a huge partner, so we're working with industry leaders to make sure that we can bring this AI revolution on-prem.
And then coming back to your question, I think we are seeing this across the board in multiple different industries. Let's start with maybe retail and quick serve restaurants, right? They have use cases around adopting vision AI and conversational AI to make their customer interactions more personalized and efficient.
They also wanna make in-store processes more efficient. So we are, we're working with some of the largest kind of quick serve restaurants around the world to deploy AI on-prem. And for them it's less a regulatory challenge.
It's more a latency and survivability issue where they have to make sure that their restaurant or retail stores stays up and running, even if connectivity to the public cloud goes down. And as you know, right, any of these restaurants are in maybe remote locations where the internet connectivity is not always the best. So that's one.
In public sector, we are seeing huge traction, again for compliance reasons, whether it's a public safety use case, like emergency responding, uh, or it's use case around sensitive financial data. Uh, we have, uh, a deployment in Luxembourg as an example where the financial regulator is deploying on-prem AI to look at, uh, financial fraud detection use cases. Yeah.
And Another example is manufacturing, right? There is assembly line worker safety that AI can help with, with vision ai, uh, or profit process efficiency in, you know, figuring out how to improve semiconductor yields with predictive AI tools. So basically we are seeing this across the board, um, and, you know, really customers are getting a huge value from this on-prem AI technology.
Yeah. You know, I was in, uh, I, I, I went to Davos, uh, this year, uh, to, to meet with folks. I was really trying to get a read on AI and investment.
Uh, everybody, you know, in the world comes there, but I wanted to get a read from, uh, folks, um, primarily in Europe, and there was a lot of talk about, Hey, I want my own sovereign cloud and I want it for, I want it for, for ai. Is this applicable? Is your technology and offering app applicable, applicable, I'll get this out, uh, to the sovereign, uh, AI cloud?
Absolutely. And I'm gonna pull back a little bit and talk about Google's approach to sovereignty and how the on-prem piece kind of ties into it. So we've been working on developing sovereign solutions for a decade or close to a decade.
I didn't know that. Thank you for pointing that out. Yeah, and we've been iterating on this over the last almost 10 years.
We recently announced kind of an updated view of our portfolio on sovereignty, and I'm gonna talk about that right now. So we believe that, you know, customers have the choice, and we are providing them with the right level of controls and technologies to enable the level of sovereignty that they need. So on Google Public Cloud, we have Google Cloud data boundary.
It allows them to control where in our public cloud regions their data is stored and processed. It allows them to store and manage their encryption keys. And those encryption fees are always in their control, which can help customers meet specific, you know, data access and control requirements.
So that's one, uh, sovereign solution that we offer. The other one that, and specifically in Europe is called Google Cloud Connected, where we work with a local partner and we basically deploy Google Cloud in an independent dedicated region. Yeah.
As an example, Google Cloud has partnered with Thais, uh, in the last four years to build out a trusted cloud solution. It's, uh, it's a, it's a partnership called SOS for Europe, and that's something that we've seen a lot getting a lot of traction now. And then last but not least, we do have a air gapped on-prem option for a fully standalone solution that does not require connectivity to any external network or to the internet.
And this is really tailored for customers in the national security space, defense intelligence, where they have the strictest of data regulations and residency requirements. And it can be deployed at a relatively small scale or a very small scale. And this can be operated by a local partner by Google themselves, if that doesn't break sovereignty rules or by a, the customer, right?
So we are offering basically a choice of sovereignty solutions depending on public sector requirements. Yeah. When I, when I learned about the OGAP solution, I, I, I said to myself, wow, this has got to get Google out of that comfort zone, uh, and was probably very difficult.
Uh, to pull off choice is, uh, is, is important. Um, and I think just the fact that you're, you're offering these things is a, is a, a really good message that you're sending, uh, to folks that you know, quite frankly, you can do it. Like you wanna do it, you wanna do it in, in the public cloud, great.
You wanna do it on-prem, we can do that too. So, and I think you've been, um, making pretty massive infrastructure, uh, uh, investments across cloud regions, across zones, network edge locations, and pops and, um, I, I am amazed to, uh, at your laying cable underneath the sea Yeah. Uh, to, to increase that performance between data centers.
Yeah. And thank you for calling that out. Right at this point, our infrastructure footprint has scaled massively, right?
We are now available in 42 public cloud regions. We have 127 zones, 200 plus network edge locations, and now 33 sub C cable investments. And that basically spans global infrastructure.
And, and I believe that we are uniquely differentiated in this space. Yeah, you do actually have the largest data state when I, you know, I put the Google cloud plus the consumer, uh, stuff, uh, stuff in there that I know a lot of people, uh, don't, don't, uh, don't, don't talk about. So, hey, I wanna talk, uh, about something pretty, pretty exciting to me, maybe looking, looking at over the next five to 10 years.
Not asking you to, you know, pre-announce, uh, what you're doing here, but more about what are the trends and the capabilities that, that you're monitoring and looking at for, uh, on-premises ai. Yeah, so I think, let's start with people think about when they talk about ai, they typically talk about models, but models are just one part of the overall AI stack. 5, or there are task specific models.
So we are gonna constantly innovate and come out with the best in class models with some of the largest context windows. 5, for example, has context windows that are the highest in the industry, going from 1 million to 2 million. And that just allows customers to process a whole lot of data in a single query.
But we are gonna see these models continuously learn and evolve and continue to get better over time. This is clearly an area that we are full focused on, but outside of models, it's really the AI platform that we are really excited about. Like Google has created best in class serving fine tuning and training platforms.
So you will likely take some of these models that, that we build, and then you will fine tune them to make them work better in your environment, in your industry. So you gotta look at how to refine their understanding, uh, you know, improve their performance and adapt their behavior. And when, when it comes to on-prem, you're going to use your local data to train this model based on your use case.
So that makes it tremendously exciting. This allows customers to kind of operate with greater autonomy, uh, and, and really the, the sovereign use cases we talked about and beyond models and the AI platform, it's the agent AI applications that are really going to be differentiated, right? Ultimately, models and AI platforms are a way for customers to create agent AI tools.
Sometimes we will provide agent AI applications directly to customers on-prem. In other cases, they will build their own tools. And a really interesting example of an agent AI tool is our recently announced agents based search on Google distributed cloud.
Now, think about the problems with search. I mean, actually, let's think about Google. Like Google is good at many things, but what made Google Google was Google search.
So think about bringing the power of Google search on-prem so that customers can really search through their own enterprise data. And today that enterprise data is completely siloed with multiple tools across teams, and we are bringing the power of Google search with large language models into on-prem deployments. And this is one of the agenda AI tools that I am personally really excited about.
And when we have shared this with customers, they've been super excited. Yeah, I'm still waiting for Vertex ai. No, I'm just kidding.
Well, We do have some Vertex AI capabilities. So, um, as part of the AI platform, uh, a few of our key Vertex AI capabilities are available on-prem, including things like, you know, language translation from, uh, 200 plus languages as well as speech to text. Uh, so we do have some elements of our Vertex AI platform on-prem as well.
Yeah, I appreciate you sharing, uh, with us kind of what the future, uh, might look like. And, you know, when I step back and gosh, I'm leaving next two weeks from now, I'm gonna be with a room full of CIOs and, you know, they just keep perpetually telling me like, I'd, I'd like some choice, but wouldn't it be great if I could closely partner with somebody, uh, who's very strong in the public cloud, and I'll call it the, the on-premises, uh, uh, AI cloud that I can, I can bank on. And, um, what you're pulling, pulling together here, I will say, and as an analyst, I always need to watch how I say it or my excitement, but I, I really like what you're, what you're putting together here.
Thank you, Patrick. We appreciate that. We wanna bring the best of Google Cloud AI to our on-prem customers and we are gonna continue to keep innovating across the stack.
Yeah. Exciting. Thanks for coming on again.
Thank You so much. Yep. So thanks for joining us here in the Intelligent Edge spotlight of the six five Summit 2025.
com. Uh, stick around. We've got more AI insights to come.
Thanks. A lot.